{"repo":"rabbitstack/fibratus","free":true,"listed":false,"github":"https://github.com/rabbitstack/fibratus","clone":"git clone https://github.com/rabbitstack/fibratus.git","description":"Security sensor for realtime threat detection and protection","language":"Go","stars":2526,"topics":["windows","windows-kernel","instrumentation","python","golang","security","edr","adversary","blueteam","etw"],"license":null,"category":"security-tools","readme_excerpt":"Fibratus Security sensor for realtime threat detection and protection Get Started » Docs &nbsp;&nbsp;&bull;&nbsp;&nbsp; Rules &nbsp;&nbsp;&bull;&nbsp;&nbsp; Filaments &nbsp;&nbsp;&bull;&nbsp;&nbsp; Download &nbsp;&nbsp;&bull;&nbsp;&nbsp; Discussions Fibratus detects and eradicates advanced attacker tradecraft, malware, and emerging threats by scrutinizing and asserting a wide spectrum of system events against a behavior-driven rule engine and YARA memory scanner. Events can be routed to a wide range of output sinks or written to capture files for local inspection and forensic analysis. With filaments, you can extend Fibratus with your own tooling and tap into the full power of the Python ecosystem. In a nutshell, the Fibratus mantra is built on three pillars: realtime behavior detection , memory scanning , and forensics . Get Fibratus Running The fastest way to install Fibratus is to run the following command from an elevated PowerShell terminal: That's it. The installer downloads and sets up the latest version of Fibratus. Once installed, follow the Quick Start to see Fibratus detect your first security event in real time. Prefer a manual installation? See the Installation Guide for alternative installation methods and detailed instructions. Learn Go beyond the quick start and learn how Fibratus works under the hood. Explore the fundamentals, understand how Fibratus observes system activity, and learn how to build rules that detect and respond to threats. Contribute We love ","default_branch":null,"files":null,"tree":[],"storefront":"/r/rabbitstack","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/rabbitstack/fibratus/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}