Skip to content
#

mitre-attack

Here are 29 public repositories matching this topic...

Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.

  • Updated Jul 28, 2026
  • Rust

Single-binary, local-first Linux security intelligence: collect host context (/proc, /etc, packages, SSH, cron, containers, …), log tails (auth, syslog/messages, journal, audit), running processes, cron, bash history samples, and optional WASM plugins; run 75+ built-in heuristic rules plus optional TOML rules (including SigmaHQ Linux rules imported

  • Updated Apr 14, 2026
  • Rust

DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI

  • Updated Jul 29, 2026
  • Rust

Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.

  • Updated Jul 27, 2026
  • Rust

Improve this page

Add a description, image, and links to the mitre-attack topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the mitre-attack topic, visit your repo's landing page and select "manage topics."

Learn more