
Windows, Linux और macOS के लिए endpoint detection। native telemetry पर Sigma, YARA और IOC rules। Rust में लिखा गया। किसी cloud account की आवश्यकता नहीं।
ओपन-सोर्स एंडपॉइंट डिटेक्शन। तीन प्लेटफ़ॉर्म। आपके नियम।
नेटिव Windows, Linux, और macOS टेलीमेट्री पर Sigma, YARA, और IOC डिटेक्शन चलाएँ।
Rust में लिखा गया, स्थानीय अलर्ट के साथ और किसी क्लाउड अकाउंट की आवश्यकता नहीं।
डाउनलोड | दस्तावेज़ीकरण | डिटेक्शन पैक | वेबसाइट
rustinel sigma doctor बताता है कि कौन से नियम फायर हो सकते हैं, जबकि rustinel doctor रनटाइम स्वास्थ्य और लोड के तहत छोड़े गए इवेंट्स की रिपोर्ट करता है।स्थानीय rustinel फ़ोल्डर में इंस्टॉल करें, फिर इसे शुरू करें।
Linux (kernel 5.8+):
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run
Windows, एक elevated PowerShell में:
irm https://rustinel.io/install.ps1 | iex
Set-Location rustinel; .\rustinel.exe run
macOS (प्रायोगिक) के लिए पहले Full Disk Access आवश्यक है, देखें macOS permissions:
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run
किसी अन्य टर्मिनल में whoami चलाएँ।
डेमो नियम फायर होता है और अलर्ट rustinel/logs/alerts.json.<date> में पहुँचता है।
इसे एक वास्तविक rules pack के साथ सेवा के रूप में इंस्टॉल करने के लिए, Ctrl-C से इसे रोकें और rustinel फ़ोल्डर से sudo ./rustinel setup --yes चलाएँ (Windows पर .\rustinel.exe setup --yes)।
देखें Deploy on an endpoint।
sudo ./rustinel capture --output ~/captures/session.ndjson # Ctrl-C when done
sudo chown -R "$USER" ~/captures
./rustinel replay ~/captures/session.ndjson
./rustinel replay ~/captures/session.ndjson --config candidate.toml
रीप्ले के लिए किसी विशेषाधिकार की आवश्यकता नहीं है और यह प्लेटफ़ॉर्म्स के बीच काम करता है: एक Windows रिकॉर्डिंग Linux पर रीप्ले होती है। देखें Test rules with replay।
| Platform | Sensors | Telemetry | Status |
|---|---|---|---|
| Windows 10/11, Server 2016+ | ETW + Windows Event Log | Process, image load, network, file, registry, DNS, PowerShell, WMI, service, task, Security audit events | Stable |
| Linux 5.8+ | eBPF | Process, network, file, DNS | Stable |
| macOS 11+ | Endpoint Security + /dev/bpf | Process, file, network, DNS | Experimental |
विवरण: Platform coverage और Limitations।
Rustinel एंडपॉइंट मॉनिटरिंग, डिटेक्शन इंजीनियरिंग, लैब्स, और SIEM पाइपलाइन परीक्षण के लिए बनाया गया है। यह किसी व्यावसायिक EDR का विकल्प नहीं है: इसमें न anti-tamper है, न pre-execution blocking, और न ही कोई management console। देखें Security model।
बग रिपोर्ट, डिटेक्शन परीक्षण, और प्लेटफ़ॉर्म कार्य का स्वागत है। बताएँ आप क्या मॉनिटर करते हैं और कहाँ अटकते हैं।
Contributing | Issues | Development guide | Roadmap