Semantic shell command safety classifier — AST-based risk scoring for AI coding agents
-
Updated
Jun 13, 2026 - Rust
Semantic shell command safety classifier — AST-based risk scoring for AI coding agents
A malware analysis platform built in Rust
Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.
Single-binary, local-first Linux security intelligence: collect host context (/proc, /etc, packages, SSH, cron, containers, …), log tails (auth, syslog/messages, journal, audit), running processes, cron, bash history samples, and optional WASM plugins; run 75+ built-in heuristic rules plus optional TOML rules (including SigmaHQ Linux rules imported
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
Ring -1 engine for MitM attacks on CPU registers. Leverages $DR0$-$DR7$ for zero-footprint interception, real-time data sniffing, and active argument tampering via WriteProcessMemory. Facilitates EDR bypass without modifying app code.
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
Initial Assessment tool for Malware Analysis made with Rust.
Defense-only AI attack detection daemon for small businesses. Watches logs, detects AI-orchestrated cyberattacks, blocks malicious IPs. Hebbian learning. MITRE ATT&CK mapped. Apache 2.0.
AI-powered Wazuh alert triage and response platform — MITRE ATT&CK insights and automated GitLab incident creation over mTLS
PE (Windows executable) forensic analyzer — pe-core parses PE32/PE64 headers (sections, imports, entropy); pe-analysis grades MITRE-tagged anomalies (suspicious imports, packing/entropy, process-injection IOCs)
Classify shell commands with AST analysis and risk scoring for AI coding agents
Put your AI on a short leash. Open-source AI agent visibility tool.
Production-grade Rust library for the MITRE ATT&CK Framework - 100% coverage of all ATT&CK objects, relationships, and extended fields
High-Performance Cloud-Native Runtime Security Sensor (eBPF + Rust)
ferox
Hypothesis-driven threat hunting on temporal knowledge graphs
Open detection rules for AI agent threats — like Sigma, but for LLMs. 71 YAML rules across 9 categories.
Xerxes Project — modular pentest harness in Rust: plugin architecture, port scanner, subdomain brute, web fuzzer. For authorized security assessments.
Windows Prefetch forensic library — parse MAM/Xpress-Huffman + SCCA v30/31 (run count, last-8 run times, loaded files), grade masquerade & suspicious-location execution. Cross-platform, panic-free, no Windows API.
Add a description, image, and links to the mitre-attack topic page so that developers can more easily learn about it.
To associate your repository with the mitre-attack topic, visit your repo's landing page and select "manage topics."