u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆27Updated 8 months ago
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- A cross platform forensic parser written in Rust!☆83Updated this week
- A Rust library for parsing and evaluating Sigma rules☆12Updated 3 weeks ago
- Convert Sigma Rules to different formats☆11Updated 9 months ago
- Cyber threat intelligence crates for Rust☆15Updated last year
- A document tagging library☆30Updated 2 months ago
- Rust implementation of the DCSO Bloom filter☆28Updated 2 months ago
- Safe and performant YARA rules evaluator in Rust☆60Updated this week
- Threat hunting with Sysmon and ArangoDB Graphs☆11Updated 5 years ago
- Rust bindings for VirusTotal/Yara☆76Updated 3 months ago
- Signature engine for all your logs☆170Updated last year
- Golang library that implements a sigma log rule parser and match engine.☆96Updated 10 months ago
- LOKI2 - Simple IOC and YARA Scanner☆93Updated 10 months ago
- A parser for the MFT (Master File Table) format☆139Updated last year
- A forensic evidence acquirer☆86Updated 4 years ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆46Updated this week
- Alternative YARA scanning engine☆70Updated 2 years ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆81Updated 2 weeks ago
- A Rust library for managing eBPF programs.☆120Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆151Updated 2 months ago
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆27Updated 3 months ago
- A CALDERA plugin☆76Updated last week
- Cisco Orbital - Osquery queries by Talos☆131Updated 9 months ago
- An opensource sigma conversion tool built using pysigma☆129Updated 5 months ago
- Sigma Detection Rule Repository☆88Updated 4 years ago
- PAL (Pcap Analysis Library)☆100Updated 6 months ago
- Artifact collection tool for *nix systems☆208Updated last year
- A Go implementation and parser for Sigma rules.☆89Updated 3 weeks ago
- SOARCA - The Open Source CACAO-based Security Orchestrator!☆74Updated last week
- Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".☆14Updated 3 years ago
- Windows Thingies... but in Rust☆23Updated 2 years ago