Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. CTF
  3. Fibratus

Fibratus

NOASSERTIONGov3.0.0

A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.

Visit WebsiteGitHubGitHub
2.5k stars217 forks0 contributors

What is Fibratus?

Fibratus is a Windows security tool that detects, protects against, and hunts advanced adversary tradecraft by analyzing system events in real-time. It uses a behavior-driven rule engine and YARA memory scanning to identify malicious activities, and supports forensic analysis through event capture. The tool helps security teams monitor, alert, and investigate threats on Windows environments.

Target Audience

Security professionals, incident responders, and threat hunters working on Windows systems who need real-time detection and forensic capabilities. It is also suitable for blue teams and SOC analysts focused on adversary hunting and tradecraft analysis.

Value Proposition

Developers choose Fibratus for its integrated approach combining real-time behavior detection, memory scanning, and forensics in a single tool. Its extensibility via Python filaments and customizable rule engine allows for tailored security monitoring, making it a versatile alternative to commercial endpoint detection solutions.

Overview

Adversary tradecraft detection, protection, and hunting

Use Cases

Best For

  • Real-time detection of adversary tradecraft on Windows systems
  • Memory scanning for malware signatures using YARA rules
  • Forensic analysis and incident response investigations
  • Extending security monitoring with custom Python-based tools
  • Behavior-driven alerting and threat hunting in enterprise environments
  • Integrating security events with external logging and SIEM systems

Not Ideal For

  • Organizations with heterogeneous environments needing cross-platform (Linux/macOS) security monitoring
  • Teams seeking out-of-the-box, lightweight logging without real-time analysis or memory scanning overhead
  • Security professionals unfamiliar with Windows internals or Python scripting for custom extensions
  • Environments where minimal system impact is critical and resource-intensive tools are unacceptable

Pros & Cons

Pros

Integrated Security Pillars

Combines real-time behavior detection, YARA memory scanning, and forensic capabilities in a single tool, as emphasized in the Fibratus mantra from the README.

Customizable Rule Engine

Offers a behavior-driven rule engine with a catalog of rules and CLI commands for exploration and creation, enabling tailored threat detection based on system events.

Python Extensibility

Supports filaments for adding custom tools using Python, leveraging the Python ecosystem to extend functionality, as highlighted in the README.

Multiple Output Sinks

Ships events and alerts to various outputs like Eventlog or external systems, facilitating integration with existing security infrastructure, as noted in the key features.

Cons

Windows-Only Limitation

Exclusively designed for Windows systems, making it unsuitable for organizations with mixed or non-Windows environments, a clear restriction from the GitHub description.

Configuration Complexity

Requires in-depth knowledge of system events, rule syntax, and possibly Python for filaments, with setup involving command-line tools and external documentation, which can be daunting.

Resource Intensive Operations

Real-time event scrutiny and memory scanning with YARA may impose significant CPU and memory overhead, potentially affecting performance on resource-constrained systems.

Frequently Asked Questions

Quick Stats

Stars2,503
Forks217
Contributors0
Open Issues33
Last commit2 days ago
CreatedSince 2016

Tags

#rule-engine#windows-security#security-tooling#security#python#behavior-analysis#windows-kernel#blueteam#instrumentation#golang#yara#forensics#incident-response#windows#threat-detection

Built With

Y
YARA
P
Python

Links & Resources

Website

Included in

Security14.2kMalware Analysis13.6kCTF11.4kHoneypots10.2kIncident Response8.9k
Auto-fetched 15 hours ago

Related Projects

GhidraGhidra

Ghidra is a software reverse engineering (SRE) framework

Stars71,278
Forks7,817
Last commit2 days ago
dnSpydnSpy

.NET debugger and assembly editor

Stars29,686
Forks5,585
Last commit5 years ago
wazuhwazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Stars16,271
Forks2,392
Last commit17 hours ago
BinwalkBinwalk

Firmware Analysis Tool

Stars14,135
Forks1,818
Last commit1 month ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub