Open-source endpoint detection engine for Windows and Linux

Rustinel은 Windows와 Linux에서 네이티브 호스트 텔레메트리를 수집하고 Sigma, YARA, IOC 룰을 평가하는 오픈소스 엔드포인트 탐지 엔진입니다. Rust로 구현되어 메모리 안전성과 성능을 보장하며, ETW(Windows)와 eBPF(Linux)를 활용해 이벤트를 수집하고 공통 모델로 정규화합니다. 탐지 결과는 SIEM 친화적인 ECS NDJSON 형식으로 출력되며, 악성 프로세스 종료 같은 능동 대응 기능도 지원합니다. 현재 Windows 지원이 더 광범위하며, Linux 지원 확대와 YARA 메모리 스캔 등 기능 추가가 계획되어 있습니다.

https://github.com/Karib0u/rustinel

#endpointdetection #rust #etw #ebpf #sigma

GitHub - Karib0u/rustinel: Rustinel is an open-source endpoint detection runtime for Windows and Linux. It collects native telemetry from ETW and eBPF, normalizes events into Sysmon-style fields, evaluates Sigma, YARA, and IOC detections, and emits ECS-compatible NDJSON alerts.

Rustinel is an open-source endpoint detection runtime for Windows and Linux. It collects native telemetry from ETW and eBPF, normalizes events into Sysmon-style fields, evaluates Sigma, YARA, and I...

GitHub
Mfa-bypass ontrafeld: waarom meerfactor-authenticatie niet volstaat / Hacking / Cybercrime / Menu Onderwijs & Ontwikkeling | CyberCrimelnfo.nl | De bibliotheek van Cybercrime en Darkweb

MFA is niet onfeilbaar: ontdek hoe cybercriminelen authenticatie omzeilen met technieken zoals phishing, MFA-fatigue en sim-swapping. Leer effectieve verdedigingsstrategieën.

How to Provide Remote Incident Response During the Coronavirus Times

A New Way to Provide Remote Incident Response During the Coronavirus Times

How to Provide Remote Incident Response During the Coronavirus Times

A New Way to Provide Remote Incident Response During the Coronavirus Times

Download Guide — Advanced Threat Protection Beyond the AV

The Advanced Threat Protection Beyond the AV Guide dives deep to explain the differences between the endpoint and network-based approaches.

Snatch Ransomware Reboots Windows in Safe Mode to Bypass Antivirus

A new variant of Snatch ransomware reboots infected computers into Windows Safe Mode and only then encrypts files to avoid antivirus protection.

What You Need to Know About Next Gen EDR - EDR is still recognized as quite efficient against many of the advanced threats security professio... more: https://threatpost.com/next-gen-edr/148626/ #criticalinfrastructure #endpointdetection #processmonitoring #vulnerabilities #networksecurity #websecurity #endpoints #business #edr #smb
What You Need to Know About Next Gen EDR

EDR is still recognized as quite efficient against many of the advanced threats security professionals encounter, but today's threatscape demands Next-Gen EDR solutions.

Threatpost - English - Global - threatpost.com