vmware-archive / cbsensor-linux-kmod
Linux Kernel module for Carbon Black EDR
☆12Updated 4 years ago
Alternatives and similar repositories for cbsensor-linux-kmod
Users that are interested in cbsensor-linux-kmod are comparing it to the libraries listed below
Sorting:
- Linux endpoint events for BPF enabled systems☆24Updated 2 years ago
- This is the Linux kernel module event collector for the Carbon Black Cloud.☆18Updated last year
- Tools for parsing rulesets using the exact grammar as YARA. Written in Go.☆83Updated 2 years ago
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated 2 years ago
- Linux Kernel Runtime Integrity with eBPF☆175Updated last year
- Golang parser for OLE files☆31Updated 2 months ago
- Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"☆17Updated 3 months ago
- zer0m0n driver for cuckoo sandbox☆87Updated 8 years ago
- pyGoRE - Python library for analyzing Go binaries☆64Updated 3 years ago
- Event Trace Log file parser in pure Python☆140Updated 4 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆116Updated 2 years ago
- Community-based integrated malware identification system☆82Updated 2 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated last year
- Dectect syscall hooking using eBPF☆153Updated 2 years ago
- A short proof-of-concept how to decrypt ssl traffic WITHOUT the server private TLS certificate☆15Updated 6 years ago
- Yet another rule generator for Yara☆28Updated 4 years ago
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆63Updated 3 years ago
- Symbol hash for ELF files☆110Updated 3 years ago
- ☆40Updated 2 years ago
- Library and tools to access the Windows Event Log (EVT) format☆59Updated 10 months ago
- ☆51Updated 6 years ago
- ☆42Updated 6 years ago
- ssdeep cluster analysis for malware files☆30Updated 4 years ago
- Tools for inspecting YARA bytecode☆17Updated 4 years ago
- ☆58Updated 4 years ago
- Go implementation of the Community ID flow hashing standard☆20Updated last month
- Linux kernel rootkit using kprobes (From http://phrack.org/issues/67/6.html)☆39Updated 10 years ago
- x86 emulation and shellcode detection☆151Updated last year
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago