You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SigmaEye is a Windows process monitoring toolkit that integrates ETW and user-level monitoring with Sigma rules. It detects suspicious process behavior, LOLBins usage, and potential threats in real-time. Features include dual monitoring, DLL injection tracking, and customizable detection rules. Requires admin privileges for ETW monitoring.
ThreatFalcon: A national Rust endpoint sensor using ETW, Sysmon, and evasion signals aligned with offensive tradecraft, focused on transparency and explainability.
Real-time ransomware detection and monitoring tool for Windows using ETW, with a Python (Flask) backend, Angular dashboard, and Redis-based event pipeline for scoring, alerting, and automated response actions.
🔍 Detect threats with Rustinel, a high-performance Windows EDR agent that leverages ETW to collect telemetry and outputs alerts for easy SIEM integration.