Fibratus is a modern tool for Windows kernel exploration and observability with a focus on security. It allows trapping system-wide events like process life-cycle, file system I/O, registry modifications, and network requests, providing deep operational visibility into the Windows kernel and running processes. Events can be shipped to various output sinks or captured for local inspection and forensics analysis, with a powerful filtering engine and rules engine for threat detection. Users can extend Fibratus using filaments to leverage the Python ecosystem.
FEATURES
ALTERNATIVES
Android Loadable Kernel Modules for reversing and debugging on controlled systems/emulators.
A simple ransomware protection that intercepts and kills malicious processes attempting to delete shadow copies using vssadmin.exe.
Event Log Explorer is a software solution for viewing, analyzing, and monitoring events recorded in Microsoft Windows event logs, offering advanced features and efficient filtering capabilities.
Read-only FUSE driver for Apple File System with support for encrypted volumes and fusion drives on Linux.
CrowdStrike Falcon is a unified cybersecurity platform providing complete protection through its AI-native XDR platform.
Endpoint security platform using Moving Target Defense to prevent cyber attacks and provide adaptive exposure management and threat prevention.
Open-source tool for monitoring macOS hosts with detailed system activity insights.
Advanced malware scanning and removal tool that detects and removes various types of malware and offers additional protection with HitmanPro.Alert.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

CTIChef.com Detection Feeds
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.

ImmuniWeb® Discovery
ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.