Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/rabbitstack/fibratus

A modern tool for Windows kernel exploration and tracing with a focus on security
https://github.com/rabbitstack/fibratus

edr golang instrumentation python security windows windows-kernel

Last synced: 20 days ago
JSON representation

A modern tool for Windows kernel exploration and tracing with a focus on security

Awesome Lists containing this project

README

        

---



Fibratus

Fibratus


Adversary tradecraft detection, protection, and hunting


Get Started »





Docs
  •  
Rules
  •  
Filaments
  •  
Download
  •  
Discussions

### What is Fibratus?

Fibratus detects, protects, and eradicates advanced adversary tradecraft by scrutinizing
and asserting a wide spectrum of system events against a behavior-driven [rule engine](https://www.fibratus.io/#/filters/rules) and [YARA](https://www.fibratus.io/#/yara/introduction) memory scanner.

Events can also be shipped to a wide array of [output sinks](https://www.fibratus.io/#/outputs/introduction) or dumped to [capture](https://www.fibratus.io/#/captures/introduction) files for local inspection and forensics analysis. You can use [filaments](https://www.fibratus.io/#/filaments/introduction) to extend Fibratus with your own arsenal of tools and so leverage the power of the Python ecosystem.

In a nutshell, the Fibratus mantra is defined by the pillars of **realtime behavior detection**, **memory scanning**, and **forensics** capabilities.

### Quick start

---

- [Install](https://www.fibratus.io/#/setup/installation) Fibratus from the latest [MSI package](https://github.com/rabbitstack/fibratus/releases)
- spin up a command line prompt
- list credentials from the vault by using the `VaultCmd` tool
```
$ VaultCmd.exe /listcreds:"Windows Credentials" /all
```
- `Credential discovery via VaultCmd.exe` rule should trigger displaying the alert in the systray notification area

### Documentation

To fully exploit and learn about Fibratus capabilities, read the [docs](https://www.fibratus.io).

---


Developed with ❤️ by Nedim Šabić Šabić



Logo designed with ❤️ by Karina Slizova