awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to endgameinc/eql

Open-source alternatives to Endgameinc Eql

30 open-source projects similar to endgameinc/eql, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Endgameinc Eql alternative.

  • airbnb/binaryalertairbnb 的头像

    airbnb/binaryalert

    1,450在 GitHub 上查看↗

    BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

    Python
    在 GitHub 上查看↗1,450
  • austin-taylor/flareA

    austin-taylor/flare

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • blueteamlabs/sentinel-attackB

    BlueTeamLabs/sentinel-attack

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • brimsec/brimB

    brimsec/brim

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • clong/detectionlabclong 的头像

    clong/DetectionLab

    4,904在 GitHub 上查看↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    在 GitHub 上查看↗4,904
  • corelight/zeek2escorelight 的头像

    corelight/zeek2es

    40在 GitHub 上查看↗

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python
    在 GitHub 上查看↗40

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Find more with AI search
  • cyb3rward0g/helkCyb3rWard0g 的头像

    Cyb3rWard0g/HELK

    3,926在 GitHub 上查看↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    在 GitHub 上查看↗3,926
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • endgameinc/varnaendgameinc 的头像

    endgameinc/varna

    52在 GitHub 上查看↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    在 GitHub 上查看↗52
  • fireeye/capafireeye 的头像

    fireeye/capa

    6,062在 GitHub 上查看↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    在 GitHub 上查看↗6,062
  • foxio-llc/logslashF

    FoxIO-LLC/LogSlash

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • intelowlproject/intelowlintelowlproject 的头像

    intelowlproject/IntelOwl

    4,605在 GitHub 上查看↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    在 GitHub 上查看↗4,605
  • jandre/brosqueryJ

    jandre/brosquery

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • mitre-attack/attack-navigatormitre-attack 的头像

    mitre-attack/attack-navigator

    2,408在 GitHub 上查看↗

    Web app that provides basic navigation and annotation of ATT&CK matrices

    TypeScriptcticyber-threat-intelligencecybersecurity
    在 GitHub 上查看↗2,408
  • mitre-attack/bzarM

    mitre-attack/bzar

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • mvelazc0/orianaM

    mvelazc0/Oriana

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • netflix/dispatchNetflix 的头像

    Netflix/dispatch

    6,385在 GitHub 上查看↗

    Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid

    Python
    在 GitHub 上查看↗6,385
  • olafhartong/threathuntingolafhartong 的头像

    olafhartong/ThreatHunting

    1,186在 GitHub 上查看↗

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

    dfirmitre-attacksplunk
    在 GitHub 上查看↗1,186
  • powershellmafia/cimsweepPowerShellMafia 的头像

    PowerShellMafia/CimSweep

    658在 GitHub 上查看↗

    CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

    PowerShell
    在 GitHub 上查看↗658
  • redhuntlabs/redhunt-osredhuntlabs 的头像

    redhuntlabs/RedHunt-OS

    1,316在 GitHub 上查看↗

    Virtual Machine for Adversary Emulation and Threat Hunting

    在 GitHub 上查看↗1,316
  • sans-blue-team/deepblueclisans-blue-team 的头像

    sans-blue-team/DeepBlueCLI

    2,404在 GitHub 上查看↗

    DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs

    PowerShell
    在 GitHub 上查看↗2,404
  • security-onion-solutions/security-onionSecurity-Onion-Solutions 的头像

    Security-Onion-Solutions/security-onion

    3,123在 GitHub 上查看↗

    Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

    在 GitHub 上查看↗3,123
  • splunk/salosplunk 的头像

    splunk/salo

    92在 GitHub 上查看↗

    Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event. The purpose of this framework is to allow security practitioners, data scientists, and researchers the ability to…

    Python
    在 GitHub 上查看↗92
  • strackvibes/nrd-dbS

    StrackVibes/NRD-db

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • supercowpowers/zatS

    SuperCowPowers/zat

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • tenzir/threatbustenzir 的头像

    tenzir/threatbus

    270在 GitHub 上查看↗

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

    Python
    在 GitHub 上查看↗270
  • tenzir/vasttenzir 的头像

    tenzir/vast

    742在 GitHub 上查看↗

    Tenzir is the data pipeline engine for security teams.

    C++
    在 GitHub 上查看↗742
  • unfetter-analytic/unfetterU

    unfetter-analytic/unfetter

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0