u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆28Updated last year
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- A Rust library for parsing and evaluating Sigma rules☆19Updated 2 months ago
- A cross platform forensic parser written in Rust!☆101Updated this week
- Cyber threat intelligence crates for Rust☆16Updated 2 years ago
- A parser for the MFT (Master File Table) format☆155Updated 3 weeks ago
- Rust bindings for VirusTotal/Yara☆80Updated 2 months ago
- Cisco Orbital - Osquery queries by Talos☆136Updated last year
- Rust implementation of the DCSO Bloom filter☆29Updated 6 months ago
- Golang library that implements a sigma log rule parser and match engine.☆103Updated last year
- Artifact collection tool for *nix systems☆212Updated last year
- A document tagging library☆33Updated 10 months ago
- An implementation of a Windows Event Collector server running on GNU/Linux.☆89Updated last week
- A Go implementation and parser for Sigma rules.☆93Updated 8 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆158Updated 10 months ago
- ☆227Updated 2 months ago
- Signature engine for all your logs☆173Updated 2 years ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆169Updated last month
- PAL (Pcap Analysis Library)☆104Updated 6 months ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆213Updated this week
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆269Updated 2 years ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆84Updated last month
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆302Updated 8 months ago
- Sigma Detection Rule Repository☆92Updated 5 years ago
- Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.☆330Updated 9 months ago
- The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders…☆147Updated 6 months ago
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆874Updated 3 weeks ago
- ☆168Updated 5 years ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆56Updated this week
- A Rust library for managing eBPF programs.☆123Updated last year
- Splunk code (SPL) for serious threat hunters and detection engineers.☆289Updated 2 years ago
- siquery, a Rust osquery implementation to query system information☆59Updated 3 months ago