hillu
Proud 1x developer, dev AND ops / rust / golang (also cgo), C, Shell, Perl, Python / Linux, Debian, Ubuntu / Security, DFIR, YARA. Cyber!
Karlsruhe / Frankfurt, Germany
Pinned Repositories
edr-loadgen
Load generator for measuring overhead generated by EDRs and other logging tools on Linux
go-cpulimit
Channel-based CPU usage limiter
go-ntdll
Go interface to NTDLL functions
go-yara
Go bindings for YARA
linux-audit-parser-rs
Parser for Linux Audit logs
local-log4j-vuln-scanner
Simple local scanner for vulnerable log4j instances
local-spring-vuln-scanner
Simple local scanner for applications containing vulnerable Spring libraries
yara-rules-re
Tools for inspecting YARA bytecode
spyre
simple YARA-based IOC scanner
laurel
Transform Linux Audit logs for SIEM usage
hillu's Repositories
hillu/local-log4j-vuln-scanner
Simple local scanner for vulnerable log4j instances
hillu/go-yara
Go bindings for YARA
hillu/local-spring-vuln-scanner
Simple local scanner for applications containing vulnerable Spring libraries
hillu/go-ntdll
Go interface to NTDLL functions
hillu/edr-loadgen
Load generator for measuring overhead generated by EDRs and other logging tools on Linux
hillu/audit-documentation
Documentation and specifications
hillu/audit-userspace
Linux audit userspace repository
hillu/dumb-inject-rs
Simple DLL injection demo in Rust
hillu/go-splunk-client
Splunk REST API client
hillu/laurel
Transform Linux Audit logs for SIEM usage
hillu/linux-audit-parser-rs
Parser for Linux Audit logs
hillu/velociraptor-api-rs
Velociraptor API client in Rust
hillu/yara
The pattern matching swiss knife
hillu/apollon
Proof-of-Concept to evade auditd by writing /proc/PID/mem
hillu/asahi-installer
Asahi Linux installer
hillu/augeas
A configuration editing tool and API
hillu/codesearch
Fast, indexed regexp search over large file trees
hillu/conference-materials
hillu/cplr
Piler for running C in the shell
hillu/gimphash
Imphash-like calculation on Golang binaries
hillu/Lsass-Shtinkering
hillu/lua-mode
Emacs major mode for editing Lua
hillu/misbrands
The world's most hated IT stickers
hillu/pefile
pefile is a Python module to read and work with PE (Portable Executable) files
hillu/runner
The Runner for GitHub Actions :rocket:
hillu/spyre
simple YARA-based IOC scanner
hillu/SysmonForLinux
hillu/velociraptor
Digging Deeper....
hillu/velociraptor-docs
Documentation site for Velociraptor
hillu/vfilter
A library implementing a generic SQL like query language.