vmware-archive / cbsensor-linux-kmodLinks
Linux Kernel module for Carbon Black EDR
☆12Updated 5 years ago
Alternatives and similar repositories for cbsensor-linux-kmod
Users that are interested in cbsensor-linux-kmod are comparing it to the libraries listed below
Sorting:
- Linux endpoint events for BPF enabled systems☆24Updated 3 years ago
- The Linux port of the Sysinternals Sysmon tool.☆281Updated 4 months ago
- Tools for parsing rulesets using the exact grammar as YARA. Written in Go.☆85Updated 3 years ago
- Parse YARA rules and operate over them more easily.☆195Updated last year
- Linux Kernel Runtime Integrity with eBPF☆184Updated 2 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆119Updated last month
- Red Canary's eBPF Sensor☆113Updated 7 months ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆216Updated 6 years ago
- osquery extensions by Trail of Bits☆269Updated 2 years ago
- ☆97Updated 5 years ago
- Library and tools to access the Windows XML Event Log (EVTX) format☆226Updated last month
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Updated 5 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆139Updated 2 years ago
- Trigram database written in C++, suited for malware indexing☆130Updated last week
- Automatically generate AV byte signatures from sets of similar binaries.☆285Updated last year
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated last year
- ETW Python Library☆293Updated 2 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- BASS - BASS Automated Signature Synthesizer☆178Updated 7 years ago
- Generating YARA rules based on binary code☆219Updated 4 years ago
- ☆72Updated 7 years ago
- x86 emulation and shellcode detection☆154Updated last year
- simple YARA-based IOC scanner☆175Updated 3 weeks ago
- Suricata Verification Tests - Testing Suricata Output☆118Updated this week
- gyp: A pure Go YARA parser☆106Updated last year
- convert ELF/DWARF symbol and type information into vol3's intermediate JSON☆145Updated last year
- The current repository contains all the scripts needed to complement kernel-mode mac-a-mal malicious activity hooking on macOS to Cuckoo …☆50Updated 7 years ago
- A network packet forensics tool for SSH☆253Updated 4 years ago
- Symbol hash for ELF files☆113Updated 3 years ago
- Security ML models encoded as Yara rules☆215Updated 2 years ago