Rustinel | Karib0u
Open-source endpoint detection engine for Windows and Linux that collects ETW/eBPF telemetry and evaluates Sigma, YARA, and IOC detections.
- from
- Detection Engineering
- added
- 2026-10-10
- likes
- 0
similar
-
domcyrus/rustnet github.com
Cross-platform network monitoring TUI with process identification via eBPF/PKTAP and deep packet inspection
-
-
InnerWarden innerwarden.com
Autonomous security agent for Linux with real-time threat detection and response via 38 eBPF hooks, 48 detectors, and 23 correlation rules.
-
SELKS github.com
A Suricata-based intrusion detection system/intrusion prevention system/network security monitoring distribution.
-
matthart1983/netwatch github.com
[netwatch-tui] - Real-time network diagnostics TUI: deep packet inspection across 13 protocols (TLS, QUIC, HTTP, DNS, SSH, MQTT, SNMP, …), per-process attribution via eBPF / PKTAP, TCP retransmit analytics, JA4 fingerprinting, optional Landlock sandbox, and Flight Recorder…
-
Detection Engineering › Logging, Monitoring & Data Sources: “Open-source endpoint detection engine for Windows and Linux that collects ETW/eBPF telemetry and evaluates Sigma, YARA, and IOC detections.”