Open-source endpoint detection. Three platforms. Your rules.
Run Sigma, YARA, and IOC detections on native Windows, Linux, and macOS telemetry.
Written in Rust, with local alerts and no cloud account required.
Download | Documentation | Detection packs | Website
- Use Sigma and YARA rules. Sigma for behavior, YARA for executables and process memory, and IOC lists for hashes, IPs, domains, and paths.
- Run on Windows, Linux, and macOS. One engine, one config format, and the same Sysmon-style field names everywhere. Coverage varies by platform.
- Keep your data. The agent sends nothing home. Alerts are local ECS NDJSON files that Elastic, Splunk, or any log pipeline can ingest.
- Test rules against recorded behavior. Capture activity once, then replay it on any machine as your rules change.
- See the gaps.
rustinel doctorreports rules that can never fire and events dropped under load.
Install into a local rustinel folder, then start it.
Linux (kernel 5.8+):
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel runWindows, in an elevated PowerShell:
irm https://rustinel.io/install.ps1 | iex
Set-Location rustinel; .\rustinel.exe runmacOS (experimental) needs Full Disk Access first, see macOS permissions:
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel runRun whoami in another terminal.
The demo rule fires and the alert lands in rustinel/logs/alerts.json.<date>.
To install it as a service with a real rules pack, stop it with Ctrl-C and run sudo ./rustinel setup --yes from the rustinel folder (.\rustinel.exe setup --yes on Windows).
See Run as a service.
sudo ./rustinel capture --output ~/captures/session.ndjson # Ctrl-C when done
sudo chown -R "$USER" ~/captures
./rustinel replay ~/captures/session.ndjson
./rustinel replay ~/captures/session.ndjson --config candidate.tomlReplay needs no privileges and works across platforms: a Windows recording replays on Linux. See Write and test rules.
| Platform | Sensors | Telemetry | Status |
|---|---|---|---|
| Windows 10/11, Server 2016+ | ETW + Windows Event Log | Process, image load, network, file, registry, DNS, PowerShell, WMI, service, task, Security audit events | Stable |
| Linux 5.8+ | eBPF | Process, network, file, DNS | Stable |
| macOS 11+ | Endpoint Security + /dev/bpf |
Process, file, network, DNS | Experimental |
Details: Platform coverage and Limitations.
Rustinel is built for endpoint monitoring, detection engineering, labs, and SIEM pipeline testing. It is not a replacement for a commercial EDR: it has no kernel self-protection, pre-execution blocking, or anti-tamper, and a privileged attacker can stop it.
Bug reports, detection tests, and platform work are welcome. Tell us what you monitor and where you get stuck.

