Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
-
Updated
Aug 24, 2026 - Rust
8000
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Authorization extension for popular web-frameworks to protect your endpoints
Rust Bindings for Endpoint Security
Authorization extension for poem to validate user permissions
Fleet AI Security Posture Management (AI-SPM): client agents on each developer machine score their AI coding agents' guard surfaces (Claude Code, Cursor, Codex, Gemini CLI — permissions, hooks, sandboxes, mcp.json) and ship hash-anchored events to a central server + your SIEM. Fleet-wide posture; measures, doesn't block. Rust.
Authorization extension for Rocket
SecureExec Multi-platform EDR agent for Linux (eBPF), macOS (Endpoint Security), and Windows (ETW) — collects security events and streams them over gRPC
Rust Endpoint Agent (2025) — Windows-first telemetry agent with mTLS, zstd batching, and enterprise hardening.
Kernel-level read gate for AI agents — protected file opens are denied or routed through off-band consent before bytes reach the agent. Linux (fanotify) + macOS (Endpoint Security).
High-performance API endpoint discovery tool for security professionals and bug bounty hunters.
PoC for the LNK Stomping attack in Windows. Hijacks shortcuts to execute a VBScript Loader, chaining a background payload with the original app.
A modular Linux Endpoint Detection and Response (EDR) platform written in Rust.
Per-process credential file access control for Linux (FUSE) and macOS (Endpoint Security): Little Snitch for your secrets
Windows endpoint intelligence and local security posture with real telemetry, detections, vulnerability intelligence, and explainable scoring.
Linux eBPF/libbpf CO-RE daemon for per-process network attribution: domains, bytes, exe hashes, alerts, SQLite WAL, and live web UI.
Autonomous, on-device endpoint defender (EDR) built in Rust — decides and acts on its own, learns per machine, with a from-scratch on-device reasoning model. Built for a world where the attacker is also an AI agent.
A global immune system for endpoints. Free, real-time, behavioral defense against ransomware.
Open-source antivirus for Windows built with Rust, Tauri, YARA-X, and a security-first architecture.
"Desktop file integrity monitor in Rust — HMAC-signed SHA-256 baselines, real-time tamper detection, amber-CRT egui GUI"
Add a description, image, and links to the endpoint-security topic page so that developers can more easily learn about it.
To associate your repository with the endpoint-security topic, visit your repo's landing page and select "manage topics."