Ross ROSS = Recommend OSS · open-source software intelligence for agents

rabbitstack/fibratus

Security sensor for realtime threat detection and protection observed · 2026-08-28

github.com/rabbitstack/fibratus · homepage · Go · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

90/100

  • Activity 98
  • Release rhythm 74
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 98.5
  • age_days: 3813
  • days_rel: 14
  • days_push: 14
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

2537 stars · 220 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Fibratus is a Windows security sensor that performs realtime threat detection by analyzing kernel and system telemetry (including ETW events) against a behavior-driven rule engine and YARA memory scanner. It supports routing events to output sinks, writing capture files for forensics, and extending functionality via Python-based filaments.

Use cases

  • detect malware and attacker tradecraft on windows endpoints in realtime
  • monitor process, file, registry and network activity via etw telemetry
  • write behavioral detection rules mapped to mitre attack techniques
  • scan process memory with yara for malicious payloads
  • capture system events for forensic analysis
  • forward security events to a siem or output sinks
  • extend detection tooling with python filaments

When to choose

  • you need an open-source edr-style sensor for windows hosts
  • you want kernel-level telemetry with a flexible rule engine
  • you need memory scanning and event capture for forensics on windows

When to avoid

  • you need threat detection on linux or macos
  • you want a fully managed commercial edr with vendor support
  • your focus is network-only intrusion detection rather than endpoint telemetry

Facets

application · maturity active

security monitoring alerting logging security windows developer-tools windows edr threat-detection etw yara mitre-attack blueteam forensics kernel-telemetry

2 sources

Member repositories

RepositoryRoleHealth v2
rabbitstack/fibratusmain90

For agents

markdown · JSON · MCP: product_card(name="rabbitstack/fibratus")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem