Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
rustinel — Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required. | Kitploit
工具/GitHubGitHub/karib0u/rustinel
Indicator of Compromise (IOC) ManagementIncident Response
GitHubkarib0u/rustinel

rustinel

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

查看仓库网站
45055261天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

Rustinel

Rustinel

Open-source endpoint detection. Three platforms. Your rules.
Run Sigma, YARA, and IOC detections on native Windows, Linux, and macOS telemetry.
Written in Rust, with local alerts and no cloud account required.

CI Latest release Downloads Apache 2.0 license

Download | Documentation | Detection packs | Website

Rustinel demo

Why Rustinel?

  • Use Sigma and YARA rules. Sigma for behavior, YARA for executables and process memory, and IOC lists for hashes, IPs, domains, and paths.
  • Run on Windows, Linux, and macOS. One engine, one config format, and the same Sysmon-style field names everywhere. Coverage varies by platform.
  • Keep your data. The agent sends nothing home. Alerts are local ECS NDJSON files that Elastic, Splunk, or any log pipeline can ingest.
  • Test rules against recorded behavior. Capture activity once, then replay it on any machine as your rules change.
  • See the gaps. rustinel sigma doctor explains which rules can fire, while rustinel doctor reports runtime health and events dropped under load.

Quickstart

Install into a local rustinel folder, then start it.

Linux (kernel 5.8+):

curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run

Windows, in an elevated PowerShell:

irm https://rustinel.io/install.ps1 | iex
Set-Location rustinel; .\rustinel.exe run

macOS (experimental) needs Full Disk Access first, see macOS permissions:

curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run

Run whoami in another terminal. The demo rule fires and the alert lands in rustinel/logs/alerts.json.<date>.

To install it as a service with a real rules pack, stop it with Ctrl-C and run sudo ./rustinel setup --yes from the rustinel folder (.\rustinel.exe setup --yes on Windows). See Deploy on an endpoint.

Capture once, replay as your rules improve

sudo ./rustinel capture --output ~/captures/session.ndjson   # Ctrl-C when done
sudo chown -R "$USER" ~/captures
./rustinel replay ~/captures/session.ndjson
./rustinel replay ~/captures/session.ndjson --config candidate.toml

Replay needs no privileges and works across platforms: a Windows recording replays on Linux. See Test rules with replay.

Platform support

PlatformSensorsTelemetryStatus
Windows 10/11, Server 2016+ETW + Windows Event LogProcess, image load, network, file, registry, DNS, PowerShell, WMI, service, task, Security audit eventsStable
Linux 5.8+eBPFProcess, network, file, DNSStable
macOS 11+Endpoint Security + /dev/bpfProcess, file, network, DNSExperimental

Details: Platform coverage and Limitations.

Know the boundaries

Rustinel is built for endpoint monitoring, detection engineering, labs, and SIEM pipeline testing. It is not a replacement for a commercial EDR: it has no anti-tamper, no pre-execution blocking, and no management console. See the Security model.

Contribute

Bug reports, detection tests, and platform work are welcome. Tell us what you monitor and where you get stuck.

Contributing | Issues | Development guide | Roadmap

License

Apache 2.0.

下载工具