Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
-
Updated
Aug 24, 2026 - Rust
FFFF
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
A complete speech segmentation system using Kaldi and x-vectors for voice activity detection (VAD) and speaker diarisation.
Step-by-step guide to deploying a Wazuh SIEM/SOC home lab using the official OVA covers hypervisor networking, memory optimization for low-RAM systems, dashboard access, SSL troubleshooting, and Windows endpoint agent deployment with full screenshots.
Adaptive BadUSB/HID attack emulation + behavioral endpoint detection with the Flipper Zero. Defensive-security research: build a labeled human-vs-injected keystroke dataset, train an EDR-style detector, and red-team it with an adaptive humanized attacker.
Experimental closed-loop EDR evaluation framework, automated artifact mutation, sandboxed execution, telemetry collection, and explainable triage. Understands why detections trigger. M.Sc. Cybersecurity thesis (EPFL, 2026).
Graph-powered EDR agent with LLM threat analysis, real-time IOC matching, and chain-aware response actions
On a scale of one to America, this NextGen Norton Antivirus EDR just made enterprise-grade defense free. Built by a Norton, carrying forward a name rooted in cybersecurity history, reimagined for modern threats.
Argus. A minimal, educational EDR / endpoint monitor written in Nim. It collects process, file, and network telemetry, normalizes it, and runs a rule-based detection engine with MITRE ATT&CK mapping. Read-only and defensive by design.
"Python-based security tool for detecting suspicious processes"
Real-time macOS living-off-the-land (LOLBin) activity radar, built on the Sigma detection rule format.
Cross-platform vibe-coded (probably badly made but w.e) endpoint forensics suite. Dual SHA-256+SHA3-256 hash-chained. ML-DSA-65-signed evidence.
I implemented a speech endpoint detector that figures out where words start and stop, using short-term energy and zero-crossing rate. Works on Persian and English.
Free lightweight EDR for small teams. Monitor processes, files, and network. Detect threats with YAML rules. Web dashboard included.
Windows endpoint detection engine (detection-as-code) with MITRE ATT&CK-mapped rules, validated on 5,650 real host events with zero false positives.
Built a Sysmon-based endpoint investigation lab to analyze attacker activity from initial execution through forensic evidence collection using Sysmon event logs, MITRE ATT&CK mapping, and IOC validation.
Lightweight endpoint detection agent in Go. Process telemetry, YAML rule engine with name/cmdline/regex matching, JSON-lines alerts.
Endpoint triage system for detecting suspicious activity using Python, MITRE ATT&CK mapping, and HTML threat reports.
Deployed Sysmon on Windows 10 with a custom XML ruleset to detect process creation, LOTL techniques, and encoded PowerShell execution via MITRE ATT&CK T1059.
Collection of scripts for Fidelis CyberSecurity EDR
Linux kernel security: Rust eBPF probes, scalable telemetry (NDJSON/gRPC), MITRE ATT&CK detection-as-code, and Claude-powered SOAR triage tuned for ML workloads.
Add a description, image, and links to the endpoint-detection topic page so that developers can more easily learn about it.
To associate your repository with the endpoint-detection topic, visit your repo's landing page and select "manage topics."