Battle-tested Sysmon configuration.
Tools that monitor
Detect threats, anomalies or policy violations at runtime.
72 tools indexed
Microsoft's Sysmon, on Linux.
All-in-one honeypot platform.
Zero-trust access for SSH, K8s and more.
eBPF-based runtime security.
Open-source SIRP for incident response.
Open-source cloud-native protection platform.
Honeytoken tripwire for the Shai-Hulud npm worm.
UAC
—Unix-like artifact collector.
Zero-install cross-platform incident response and DFIR toolkit.
Endpoint visibility and DFIR.
Open-source EDR for Windows.
Open-source XDR and SIEM.
YARA
—Pattern matching for malware research.
Community YARA rule repository.
Zeek
—Network analysis framework.
Multi-layer bot detection for browser and server.
SQL-powered endpoint visibility.
pspy
—Spy on Linux processes without root.
Lightweight firewall that drives the Windows Filtering Platform directly.
Easy SSH honeypot.
Transparent SSH bastion.
Modular Sysmon configuration repo.
witr
—Trace any process, port, container or file back to what started it.