Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
-
Updated
Sep 15, 2026 - Rust
Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
A complete speech segmentation system using Kaldi and x-vectors for voice activity detection (VAD) and speaker diarisation.
CrowdStrike Falcon Sensor Deployment Doc - Desktop package for Windows with a smooth setup flow and the full pro toolkit included.
Step-by-step guide to deploying a Wazuh SIEM/SOC home lab using the official OVA covers hypervisor networking, memory optimization for low-RAM systems, dashboard access, SSL troubleshooting, and Windows endpoint agent deployment with full screenshots.
On a scale of one to America, this NextGen Norton Antivirus EDR just made enterprise-grade defense free. Built by a Norton, carrying forward a name rooted in cybersecurity history, reimagined for modern threats.
Argus. A minimal, educational EDR / endpoint monitor written in Nim. It collects process, file, and network telemetry, normalizes it, and runs a rule-based detection engine with MITRE ATT&CK mapping. Read-only and defensive by design.
Adaptive BadUSB/HID attack emulation + behavioral endpoint detection with the Flipper Zero. Defensive-security research: build a labeled human-vs-injected keystroke dataset, train an EDR-style detector, and red-team it with an adaptive humanized attacker.
Experimental closed-loop EDR evaluation framework, automated artifact mutation, sandboxed execution, telemetry collection, and explainable triage. Understands why detections trigger. M.Sc. Cybersecurity thesis (EPFL, 2026).
Graph-powered EDR agent with LLM threat analysis, real-time IOC matching, and chain-aware response actions
"Python-based security tool for detecting suspicious processes"
粤语端点检测(VAD)实验:训练脚本 + 推理端。
Real-time macOS living-off-the-land (LOLBin) activity radar, built on the Sigma detection rule format.
Windows endpoint detection engine (detection-as-code) with MITRE ATT&CK-mapped rules, validated on 5,650 real host events with zero false positives.
Cross-platform vibe-coded (probably badly made but w.e) endpoint forensics suite. Dual SHA-256+SHA3-256 hash-chained. ML-DSA-65-signed evidence.
I implemented a speech endpoint detector that figures out where words start and stop, using short-term energy and zero-crossing rate. Works on Persian and English.
Free lightweight EDR for small teams. Monitor processes, files, and network. Detect threats with YAML rules. Web dashboard included.
Deployed Sysmon on Windows 10 with a custom XML ruleset to detect process creation, LOTL techniques, and encoded PowerShell execution via MITRE ATT&CK T1059.
Endpoint triage system for detecting suspicious activity using Python, MITRE ATT&CK mapping, and HTML threat reports.
Built a Sysmon-based endpoint investigation lab to analyze attacker activity from initial execution through forensic evidence collection using Sysmon event logs, MITRE ATT&CK mapping, and IOC validation.
Lightweight endpoint detection agent in Go. Process telemetry, YAML rule engine with name/cmdline/regex matching, JSON-lines alerts.
To associate your repository with the endpoint-detection topic, visit your repo's landing page and select "manage topics."