Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
-
Updated
Aug 18, 2026 - Rust
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
A complete speech segmentation system using Kaldi and x-vectors for voice activity detection (VAD) and speaker diarisation.
Step-by-step guide to deploying a Wazuh SIEM/SOC home lab using the official OVA covers hypervisor networking, memory optimization for low-RAM systems, dashboard access, SSL troubleshooting, and Windows endpoint agent deployment with full screenshots.
Adaptive BadUSB/HID attack emulation + behavioral endpoint detection with the Flipper Zero. Defensive-security research: build a labeled human-vs-injected keystroke dataset, train an EDR-style detector, and red-team it with an adaptive humanized attacker.
Experimental closed-loop EDR evaluation framework, automated artifact mutation, sandboxed execution, telemetry collection, and explainable triage. Understands why detections trigger. M.Sc. Cybersecurity thesis (EPFL, 2026).
Graph-powered EDR agent with LLM threat analysis, real-time IOC matching, and chain-aware response actions
On a scale of one to America, this NextGen Norton Antivirus EDR just made enterprise-grade defense free. Built by a Norton, carrying forward a name rooted in cybersecurity history, reimagined for modern threats.
"Python-based security tool for detecting suspicious processes"
Argus. A minimal, educational EDR / endpoint monitor written in Nim. It collects process, file, and network telemetry, normalizes it, and runs a rule-based detection engine with MITRE ATT&CK mapping. Read-only and defensive by design.
Free lightweight EDR for small teams. Monitor processes, files, and network. Detect threats with YAML rules. Web dashboard included.
Cross-platform vibe-coded (probably badly made but w.e) endpoint forensics suite. Dual SHA-256+SHA3-256 hash-chained. ML-DSA-65-signed evidence.
I implemented a speech endpoint detector that figures out where words start and stop, using short-term energy and zero-crossing rate. Works on Persian and English.
Windows endpoint detection engine (detection-as-code) with MITRE ATT&CK-mapped rules, validated on 5,650 real host events with zero false positives.
Built a Sysmon-based endpoint investigation lab to analyze attacker activity from initial execution through forensic evidence collection using Sysmon event logs, MITRE ATT&CK mapping, and IOC validation.
Lightweight endpoint detection agent in Go. Process telemetry, YAML rule engine with name/cmdline/regex matching, JSON-lines alerts.
Endpoint triage system for detecting suspicious activity using Python, MITRE ATT&CK mapping, and HTML threat reports.
Deployed Sysmon on Windows 10 with a custom XML ruleset to detect process creation, LOTL techniques, and encoded PowerShell execution via MITRE ATT&CK T1059.
Real-time macOS living-off-the-land (LOLBin) activity radar, built on the Sigma detection rule format.
Collection of scripts for Fidelis CyberSecurity EDR
Linux kernel security: Rust eBPF probes, scalable telemetry (NDJSON/gRPC), MITRE ATT&CK detection-as-code, and Claude-powered SOAR triage tuned for ML workloads.
Add a description, image, and links to the endpoint-detection topic page so that developers can more easily learn about it.
To associate your repository with the endpoint-detection topic, visit your repo's landing page and select "manage topics."