YAIDS is a Multi-Threaded Intrusion Detection System using Yara. It's a performant, written in C, and supports any PCAP compatible data stream (Network, USB, Bluetooth, etc.). It supports BPF (traffic filtering), all valid Yara rules (including modules), and includes External Variables to build traffic/packet attribute conditions. It also includes multiple logging modes (alerts, PCAP data, console, file, etc.).
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A tool for parsing Google Protobuf encoded blobs without the accompanying definition, providing a colored representation of the contents.
An OpenFlow honeypot that detects unused IP addresses and simulates network traffic to attract and analyze potential threats
High-performance remote packet capture and collection tool used for forensic analysis in cloud workloads.
A tool for discovering open S3 Buckets starting from a domain using various techniques such as crawling and DNS crawling.
Contains various use cases of Kubernetes Network Policies and sample YAML files.
Fail2ban is a daemon that automatically bans IP addresses showing malicious behavior by monitoring log files and updating firewall rules to prevent brute-force attacks.
Intercepts and examines mobile app connections by stripping SSL/TLS layer.
LogRhythm NetMon is a network traffic analytics tool that provides real-time visibility, automated threat detection, and investigation capabilities for organizational networks.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.