rabbitstack/fibratus

Gofibratus.io
Windows

Security sensor for realtime threat detection and protection

windowswindows-kernelinstrumentationsecurityetwblue-teamdetection-engineeringendpoint-detection-responseendpoint-securitymalware-detectionmitre-attackpurple-team
Star 增长趋势
Star
2.5k
Forks
220
周增长
+0
Issues
35
1k2k
2016年5月2019年10月2023年3月2026年9月
制品库Go Modules
README

Fibratus

Fibratus

Security sensor for realtime threat detection and protection
Get Started »

Docs   •   Rules   •   Filaments   •   Download   •   Discussions

Fibratus detects and eradicates advanced attacker tradecraft, malware, and emerging threats by scrutinizing and asserting a wide spectrum of system events against a behavior-driven rule engine and YARA memory scanner.

Events can be routed to a wide range of output sinks or written to capture files for local inspection and forensic analysis. With filaments, you can extend Fibratus with your own tooling and tap into the full power of the Python ecosystem.

In a nutshell, the Fibratus mantra is built on three pillars: realtime behavior detection, memory scanning, and forensics.

Fibratus

Get Fibratus Running

The fastest way to install Fibratus is to run the following command from an elevated PowerShell terminal:

irm https://install.fibratus.io | iex

That's it. The installer downloads and sets up the latest version of Fibratus.

Once installed, follow the Quick Start to see Fibratus detect your first security event in real time.

Prefer a manual installation? See the Installation Guide for alternative installation methods and detailed instructions.

Learn

Go beyond the quick start and learn how Fibratus works under the hood. Explore the fundamentals, understand how Fibratus observes system activity, and learn how to build rules that detect and respond to threats.

Contribute

We love contributions. To start contributing to Fibratus, please read our contribution guidelines.

Code Signing Policy

Free code signing provided by SignPath.io, certificate by SignPath Foundation. All releases are automatically signed.


Developed with ❤️ by Nedim Šabić Šabić and contributors

相关仓库
massgravel/Microsoft-Activation-Scripts

Open-source Windows and Office activator featuring HWID, Ohook, TSforge, and Online KMS activation methods, along with advanced troubleshooting.

BatchfileGNU General Public License v3.0hwidkms38
massgrave.dev
189.8k18.1k
flutter/flutter

Flutter makes it easy and fast to build beautiful apps for mobile and beyond

DartlibraryBSD 3-Clause "New" or "Revised" Licensemobileandroid
flutter.dev
178.9k31.1k
jlevy/the-art-of-command-line

Master the command line, in one page

tutorialbashunix
162.3k14.8k
clash-verge-rev/clash-verge-rev

A modern GUI client based on Tauri, designed to run in Windows, macOS and Linux for tailored proxy experience

TypeScriptnpmappGNU General Public License v3.0clashclash-meta
clashverge.dev
143.2k10.3k
microsoft/PowerToys

Microsoft PowerToys is a collection of utilities that supercharge productivity and customization on Windows

CMIT Licensepowertoysdesktop
138.5k8.5k
rustdesk/rustdesk

An open-source remote desktop application designed for self-hosting, as an alternative to TeamViewer.

Rustcrates.ioappGNU Affero General Public License v3.0remote-controlremote-desktop
rustdesk.com
123k18.9k
nodejs/node

Node.js JavaScript runtime ✨🐢🚀✨

JavaScriptnpmOthernodejsjavascript
nodejs.org
121.2k36.7k
2dust/v2rayN

A GUI client for Windows, Linux and macOS, support Xray and sing-box and others

C#appGNU General Public License v3.0windowsproxy
v2rayn.2dust.link
115.7k15.9k
microsoft/terminal

The new Windows Terminal and the original Windows console host, all in the same place!

C++cliMIT Licenseconsoleterminal
104.8k9.6k
ventoy/Ventoy

A new bootable USB solution.

CappGNU General Public License v3.0bootable-usbmultiboot
ventoy.net
79.2k4.9k
alacritty/alacritty

A cross-platform, OpenGL terminal emulator.

Rustcrates.iocliApache License 2.0terminal-emulatorsopengl
alacritty.org
65.7k3.6k
tldr-pages/tldr

Collaborative cheatsheets for console commands 📚.

MarkdowntutorialOthershellman-page
tldr.sh
63.6k5.4k