plgx-esp
EDR-Testing-Script
plgx-esp | EDR-Testing-Script | |
---|---|---|
1 | 1 | |
20 | 278 | |
- | - | |
6.5 | 0.0 | |
over 2 years ago | over 2 years ago | |
CSS | Batchfile | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
plgx-esp
-
Free EDR solutions
Check out PolyLogyx ESP ( aka EclecticIQ ER community edition) if you are familiar with Osquery this offers much of the same functionality with more Windows telemetry visibility. https://github.com/polylogyx/plgx-esp
EDR-Testing-Script
-
Kaspersky Endpoint Security issue
I downloaded and executed script from GitHub, EDR Testing Script and it failed miserably. It allowed everything to be downloaded and executed, let remote shell scripts to be run, files to install, and it did that as a user. I didn't even run that script as an admin. Worse thing is, KES uninstalled itself afterwards.
What are some alternatives?
OSSEC - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
security - Collection of CVEs from Sick Codes, or collaborations on https://sick.codes security research & advisories.
fleet - A flexible control server for osquery fleets
iMonitorSDK - 系统监控开发套件(sysmon、procmon、edr、终端安全、主机安全、零信任、上网行为管理、沙箱)
xxh - 🚀 Bring your favorite shell wherever you go through the ssh. Xonsh shell, fish, zsh, osquery and so on.
Incident-Playbook - GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
DetectionLab - Automate the creation of a lab environment complete with security tooling and logging best practices
WhiteBeam - WhiteBeam: Transparent endpoint security
lme - Logging Made Easy
Atlas - 🚀 An open and lightweight modification to Windows, designed to optimize performance, privacy and security.
Elkeid - Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.
Wazuh - Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.