u-siem / u-siem-core
Framework definitions that allow to build a custom SIEM.
☆25Updated last month
Related projects ⓘ
Alternatives and complementary repositories for u-siem-core
- A cross platform forensic parser written in Rust!☆67Updated last week
- Cyber threat intelligence crates for Rust☆13Updated 10 months ago
- A document tagging library☆29Updated last year
- Safe and performant YARA rules evaluator in Rust☆45Updated last month
- Rust implementation of the DCSO Bloom filter☆26Updated last month
- Rust bindings for VirusTotal/Yara☆77Updated last month
- File Capability Extractor☆12Updated last week
- Cisco Orbital - Osquery queries by Talos☆123Updated 2 months ago
- A forensic evidence acquirer☆85Updated 3 years ago
- LOKI2 - Simple IOC and YARA Scanner☆80Updated 3 months ago
- A Go implementation and parser for Sigma rules.☆84Updated 2 months ago
- A parser for the MFT (Master File Table) format☆128Updated last year
- Artifact collection tool for *nix systems☆192Updated 8 months ago
- Signature engine for all your logs☆161Updated last year
- A CALDERA plugin☆72Updated 3 weeks ago
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆23Updated 7 months ago
- A set of PCAPs used to test the parsers used by Malcolm. Also, a curated list of PCAP collections I've found online.☆32Updated this week
- Sigma Detection Rule Repository☆85Updated 4 years ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆32Updated this week
- Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".☆14Updated 3 years ago
- Threat hunting with Sysmon and ArangoDB Graphs☆11Updated 4 years ago
- ☆34Updated 3 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- A MITRE Caldera plugin☆38Updated this week
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆14Updated this week
- Golang library that implements a sigma log rule parser and match engine.☆92Updated 4 months ago
- A Rust library for managing eBPF programs.☆116Updated 8 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆141Updated last year