Awesome Cybersecurity Blue Team
Section: Host-based tools · Locally checks for signs of a rootkit on GNU/Linux systems.
Entry
Appears in 4 awesome lists
用于在GNU / Linux系统上本地检查rootkit的迹象; 补充,Rootkit:常指被作为驱动程序,加载到操作系统内核中的恶意软件
Section: Host-based tools · Locally checks for signs of a rootkit on GNU/Linux systems.
Section: 主机防护工具 · 用于在GNU / Linux系统上本地检查rootkit的迹象; 补充,Rootkit:常指被作为驱动程序,加载到操作系统内核中的恶意软件
Section: Detection and Classification · Local Linux rootkit detection.
Section: Linux Defenses · Locally checks for signs of a rootkit.
is a free, open-source host-based intrusion detection system. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, time-based alerting, and active response.
An Obfuscation-Neglect Android Malware Scoring System.
Generator for YARA rules - The main principle is the creation of yara rules from strings found in malware files while removing all strings that also appear in goodware files.
Static Linker/Compiler/Tool detector for Windows, Linux and MacOS.
Robust parser for PE files with a flexible plugin architecture which allows users to statically analyze files in-depth.
Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
Platform-independent Perl library plus a command-line application for reading, writing and editing meta information in a wide variety of files.
POSIX-compliant Bash script that scans a host for various signs of malware.