kunai

Event monitor

An eBPF-based tool for comprehensive Linux event monitoring and analysis

Threat-hunting tool for Linux

GitHub

403 stars
11 watching
23 forks
Language: Rust
last commit: about 2 months ago
ebpflinuxsecurity-monitoringthreat-detectionthreat-hunting

Related projects:

Repository Description Stars
ninoseki/mihari An aggregator tool for querying multiple services to gather threat intelligence data. 870
a3sal0n/cyberthreathunting A collection of tools and resources for threat hunters to identify and respond to cyber threats. 861
threathuntingproject/threathunting An informational repository providing resources and knowledge for detecting adversaries in IT environments. 1,726
miladaslaner/threathunt A PowerShell repository to simulate and train threat hunting skills without malicious files. 134
gossithedog/threathunting Tools and rules for detecting malicious domain calls in endpoint malware 570
sk4la/plast A modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations. 17
opencybersecurityalliance/kestrel-lang A language and runtime framework for building reusable, composable threat hunting workflows using Python. 302
otrf/threathunter-playbook A community-driven project providing shared detection logic and resources for threat hunting 4,049
sbousseaden/slides Collection of resources and concepts for threat hunting and detection engineering. 372
fr0gger/yeti An open-source platform designed to collect, organize, and provide insights on threat intelligence data 1
aboutsecurity/rastrea2r A tool for hunting and tracking Internet of Things (IoT) security threats by collecting and analyzing indicators of compromise (IOCs) 116
matamorphosis/scrummage A platform for searching and analyzing publicly available online data to detect potential security threats 515
sapphirex00/threat-hunting A collection of threat intelligence resources and tools for analyzing APT malware 257
kasperskylab/klara Helps Threat Intelligence researchers hunt for new malware by efficiently scanning large collections of files with Yara rules 698
netevert/sentinel-attack A tool to quickly deploy a threat hunting capability on Azure Sentinel using Sysmon and MITRE ATT&CK 1,062