Rust Windows EDR (user-mode, no driver): ETW → Sysmon-style normalization → Sigma/Yara/IOC detection → ECS NDJSON alerts.
Rustinel is a lightweight Windows security monitor that detects threats by watching system activity and alerting on suspicious behavior.
How It Works
You find this free Windows security helper on GitHub that watches for bad activity without slowing down your computer.
Grab the latest ready-to-use file from the releases page and unzip it to a folder on your Windows machine.
Right-click and run as administrator to start watching your computer's processes, files, and network in real time.
Try the built-in test like running 'whoami' and watch it catch suspicious activity, saving alerts to simple log files.
Install it as a background service so it starts every time your computer boots and keeps protecting quietly.
Adjust what it watches or add custom rules for specific threats using the easy settings file.
Your Windows machine now detects threats like malware or odd behavior automatically, with clear alerts ready to review.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.