Awesome Cybersecurity Blue Team
Section: Host-based tools · Fully open source and free, feature-rich, Host-based Instrusion Detection System (HIDS).
Entry
Appears in 4 awesome lists
is a free, open-source host-based intrusion detection system. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, time-based alerting, and active response.
Section: Host-based tools · Fully open source and free, feature-rich, Host-based Instrusion Detection System (HIDS).
Section: 主机防护工具 · 完全开源、免费的,功能丰富的基于主机的入侵检测系统(HIDS)
Section: Intrusion Detection · OSSEC is an Open Source host-based intrusion detection system, that performs log analysis, integrity checking, monitoring, rootkit detection, real-time alerting and active response.
Section: Security Tools · is a free, open-source host-based intrusion detection system. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, time-based alerting, and active response.
(formerly Bro) is an open source software platform that provides compact, high-fidelity transaction logs, file content, and fully customized output to analysts, from the smallest home office to the largest, fastest research and commercial networks. From the FAQ: "Zeek provides a comprehensive…
用于在GNU / Linux系统上本地检查rootkit的迹象; 补充,Rootkit:常指被作为驱动程序,加载到操作系统内核中的恶意软件
POSIX-compliant Bash script that scans a host for various signs of malware.
is a tool for Linux that allows to create multiple hidden volumes on a storage device in such a way that it is very difficult, even under forensic inspection, to prove the existence of such volumes.
Both a library and a command line tool (oscap) used to evaluate a system against SCAP baseline profiles to report on the security posture of the scanned system(s).
An 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.
picosnitch helps protect your security and privacy by "snitching" on anything that connects to the internet, letting you know when, how much data was transferred, and to where. It uses BPF to monitor…
SNARE (System iNtrusion Analysis and Reporting Environment) is a series of log collection agents that facilitate centralized analysis of audit log data. Logs from the OS are collected and audited. Ful…