vmware-archive / cbsensor-linux-kmodLinks
Linux Kernel module for Carbon Black EDR
☆12Updated 4 years ago
Alternatives and similar repositories for cbsensor-linux-kmod
Users that are interested in cbsensor-linux-kmod are comparing it to the libraries listed below
Sorting:
- Linux endpoint events for BPF enabled systems☆24Updated 2 years ago
- Tools for parsing rulesets using the exact grammar as YARA. Written in Go.☆85Updated 2 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆116Updated 2 years ago
- Rootkit Detector for UNIX☆61Updated last year
- This is the Linux kernel module event collector for the Carbon Black Cloud.☆18Updated last year
- ☆52Updated 6 years ago
- A tool for de-obfuscating PowerShell scripts☆68Updated 6 years ago
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆63Updated 3 years ago
- zer0m0n driver for cuckoo sandbox☆87Updated 8 years ago
- Automatically generate AV byte signatures from sets of similar binaries.☆273Updated 6 months ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆132Updated 2 years ago
- Community-based integrated malware identification system☆82Updated 2 years ago
- Using LibVMI to detect malware☆31Updated 3 years ago
- Trigram database written in C++, suited for malware indexing☆125Updated 8 months ago
- The current repository contains all the scripts needed to complement kernel-mode mac-a-mal malicious activity hooking on macOS to Cuckoo …☆50Updated 7 years ago
- Parse YARA rules and operate over them more easily.☆191Updated 4 months ago
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆58Updated 2 years ago
- Pure Python parser for data encoded by .NET's BinaryFormatter☆50Updated 6 years ago
- Signature engine for all your logs☆170Updated last year
- Linux kernel rootkit using kprobes (From http://phrack.org/issues/67/6.html)☆38Updated 10 years ago
- Find strings in Go binaries☆53Updated 5 years ago
- Tools for inspecting YARA bytecode☆17Updated 4 years ago
- Sysmon config for both Windows and Linux Devices. Windows one is a bit dated☆57Updated 11 months ago
- ConventionEngine - A Yara Rulepack for PDB Path Hunting☆38Updated 2 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 7 years ago
- ☆59Updated 4 years ago
- Symbol hash for ELF files☆111Updated 3 years ago