u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆27Updated 10 months ago
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- A Rust library for parsing and evaluating Sigma rules☆14Updated 3 months ago
- A cross platform forensic parser written in Rust!☆92Updated this week
- Cyber threat intelligence crates for Rust☆16Updated last year
- Rust implementation of the DCSO Bloom filter☆28Updated 3 weeks ago
- Rust bindings for VirusTotal/Yara☆78Updated 5 months ago
- A parser for the MFT (Master File Table) format☆145Updated 2 years ago
- Golang library that implements a sigma log rule parser and match engine.☆95Updated last year
- FIM is an Open Source Host-based file integrity monitoring tool that performs file system analysis, file integrity checking, real time al…☆163Updated this week
- Safe and performant YARA rules evaluator in Rust☆66Updated last month
- A Rust library for managing eBPF programs.☆121Updated last year
- Signature engine for all your logs☆171Updated last year
- Cisco Orbital - Osquery queries by Talos☆134Updated 11 months ago
- Graph platform for Detection and Response☆696Updated 2 years ago
- LOKI2 - Simple IOC and YARA Scanner☆98Updated last month
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆315Updated 10 months ago
- A Go implementation and parser for Sigma rules.☆88Updated 2 months ago
- A document tagging library☆30Updated 4 months ago
- Artifact collection tool for *nix systems☆208Updated last year
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆787Updated last month
- An implementation of a Windows Event Collector server running on GNU/Linux.☆76Updated this week
- Sigma rules from Joe Security☆217Updated 9 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆153Updated 5 months ago
- OSSEM Detection Model☆176Updated 2 years ago
- Threat hunting with Sysmon and ArangoDB Graphs☆11Updated 5 years ago
- The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders…☆143Updated last month
- Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).☆413Updated last year
- A standard for reducing log volume without sacrificing analytical capability☆207Updated 5 months ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆291Updated 3 months ago
- ☆221Updated last year
- SOARCA - The Open Source CACAO-based Security Orchestrator!☆76Updated this week