
Archived
SilkETW
用于ETW的C#封装器,将内核和用户模式事件数据序列化为JSON,用于威胁狩猎、恶意软件分析和事件响应,集成了Yara并支持发送至Elasticsearch。
defensive-toolsmemory-forensicsforensics+8
852

⭐ ⭐ 适用于云原生环境的分布式 tcpdump ⭐ ⭐

以编程方式创建用于反序列化利用的搜索规则,支持多种关键词、利用链、对象类型、编码和规则类型

Express Linux 服务器安全基础部署

By Kprobe technology 开源基于主机的入侵检测系统(HIDS),来自 E_Bwill。

Stenographer 是一款数据包捕获解决方案,旨在快速将所有数据包暂存到磁盘,然后提供对这些数据包子集的简单、快速访问。讨论/公告请发送至 [email protected]

OWASP ModSecurity核心规则集(CRS)项目(官方仓库)

HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints can be…

集中管理入侵检测系统,例如 Suricata、Bro、Ossec ...

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management