Skip to content
 
 

Repository files navigation

Fibratus PyPI version

Build status Coverage Status Code Health

Fibratus is a tool which is able to capture the most of the Windows kernel activity - process/thread creation and termination, context switches, file system I/O, registry, network activity, DLL loading/unloading and much more. The kernel events can be easly streamed to a number of output sinks like AMQP message brokers, Elasticsearch clusters or standard output stream. You can use filaments (lightweight Python modules) to extend Fibratus with your own arsenal of tools and so leverage the power of the Python's ecosystem.

Requirements

  • Python 3.4
  • Visual C++ 2012 or above
  • Cython >=0.23.4

Installation

Install via the pip package manager:

pip install fibratus

Documentation

See the wiki.

Support

Beerpay Beerpay OpenCollective OpenCollective

About

Security sensor for realtime threat detection and protection

Topics

Resources

Stars

2.5k stars

Watchers

66 watching

Forks

Releases

Sponsor this project

Used by

Contributors

Languages