rustinel is a free, open source threat detection & response project written in Rust and released under Apache-2.0. It has 501 GitHub stars, 62 forks and 60 open issues, and was last pushed 10 hours ago. On this registry it ranks #58 of 58 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is rustinel?

Rustinel is an open-source endpoint detection agent for Windows, Linux, and macOS that runs Sigma, YARA, and IOC rules against native telemetry locally, with no cloud account required.

What it is

Rustinel is a cross-platform endpoint detection agent written in Rust, licensed under Apache-2.0, and operated entirely on the endpoint it monitors. It evaluates three kinds of detection content: Sigma rules for behaviour, YARA rules for executables and process memory, and IOC lists covering hashes, IPs, domains, and paths. Alerts are written locally as ECS NDJSON files that Elastic, Splunk, or any log pipeline can ingest, and the agent sends nothing home. It lives in the endpoint security and detection engineering ecosystem, where it replaces a cloud-managed EDR agent for teams that want detection rules running against native telemetry without registering an account or shipping data to a vendor.

The concrete problem it addresses is testing and running detections against real endpoint behaviour without surrendering data to a hosted service. On Windows it reads ETW and Windows Event Log telemetry; on Linux 5.8+ it uses eBPF; on macOS 11+ it uses Endpoint Security and /dev/bpf. A single engine, one config format, and Sysmon-style field names apply across all three, although coverage varies by platform.

Key capabilities

  • Runs Sigma rules for behaviour, YARA rules for executables and process memory, and IOC lists for hashes, IPs, domains, and paths against local telemetry.
  • Captures activity once with rustinel capture --output ~/captures/session.ndjson and replays it later with rustinel replay against improving rules, needing no privileges and working across platforms — a Windows recording replays on Linux.
  • Reports on rule coverage and runtime health through rustinel sigma doctor, which explains which rules can fire, and rustinel doctor, which reports runtime health and events dropped under load.
  • Emits alerts as local ECS NDJSON files in rustinel/logs/alerts.json for ingestion by Elastic, Splunk, or any log pipeline.
  • Provides telemetry across platforms: Windows 10/11 and Server 2016+ (process, image load, network, file, registry, DNS, PowerShell, WMI, service, task, Security audit events), Linux 5.8+ (process, network, file, DNS), and macOS 11+ (process, file, network, DNS).
  • Installs and runs as an endpoint service via rustinel setup --yes from the rustinel folder, in addition to foreground operation with rustinel run.
  • Ships detection packs and documentation at docs.rustinel.io for rule sets and operations guidance.

Who uses it and how

  • Detection engineers test Sigma and YARA rules by capturing a session once and replaying it on any machine as rules change, including re-running a recording under a candidate.toml configuration.
  • Blue teams and incident responders monitor endpoints where they want alerts kept locally as ECS NDJSON rather than sent to a vendor cloud.
  • Analysts feeding Elastic, Splunk, or another log pipeline ingest Rustinel's alert files alongside existing telemetry.
  • Teams running SIEM pipeline testing exercise recorded endpoint behaviour without provisioning an EDR management console.
  • Lab and Linux security practitioners deploy on Linux 5.8+ hosts, with macOS treated as experimental and requiring Full Disk Access first.

Getting started

Install into a local rustinel folder with curl -fsSL https://rustinel.io/install.sh | sh, then start it with cd rustinel && sudo ./rustinel run; on Windows, run irm https://rustinel.io/install.ps1 | iex in an elevated PowerShell and start .\rustinel.exe run.

How it compares

Among similar tools named in these facts, Rustinel is positioned explicitly against commercial EDR, which it states it is not a replacement for: it has no anti-tamper, no pre-execution blocking, and no management console. It fits instead as an endpoint monitoring, detection engineering, lab, and SIEM pipeline testing tool that keeps data on the endpoint under an Apache-2.0 licence.

When to use it — and when not

A self-hoster runs the agent itself and operates the downstream log pipeline, since alerts are local ECS NDJSON files that need Elastic, Splunk, or another ingester; Linux requires kernel 5.8+, macOS needs Full Disk Access, and macOS support is experimental with coverage varying by platform. Do not pick it if you need anti-tamper, pre-execution blocking, or a management console — Rustinel states plainly it is not a replacement for a commercial EDR — and note that the project carries 60 open issues alongside its 501 stars.

project readme (upstream, from github) — read inline

Rustinel

Open-source endpoint detection. Three platforms. Your rules.
Run Sigma, YARA, and IOC detections on native Windows, Linux, and macOS telemetry.
Written in Rust, with local alerts and no cloud account required.

CI Latest release Downloads Apache 2.0 license

Download | Documentation | Detection packs | Website

Why Rustinel?

  • Use Sigma and YARA rules. Sigma for behavior, YARA for executables and process memory, and IOC lists for hashes, IPs, domains, and paths.
  • Run on Windows, Linux, and macOS. One engine, one config format, and the same Sysmon-style field names everywhere. Coverage varies by platform.
  • Keep your data. The agent sends nothing home. Alerts are local ECS NDJSON files that Elastic, Splunk, or any log pipeline can ingest.
  • Test rules against recorded behavior. Capture activity once, then replay it on any machine as your rules change.
  • See the gaps. rustinel sigma doctor explains which rules can fire, while rustinel doctor reports runtime health and events dropped under load.

Quickstart

Install into a local rustinel folder, then start it.

Linux (kernel 5.8+):

curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run

Windows, in an elevated PowerShell:

irm https://rustinel.io/install.ps1 | iex
Set-Location rustinel; .\rustinel.exe run

macOS (experimental) needs Full Disk Access first, see macOS permissions:

curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel && sudo ./rustinel run

Run whoami in another terminal. The demo rule fires and the alert lands in rustinel/logs/alerts.json..

To install it as a service with a real rules pack, stop it with Ctrl-C and run sudo ./rustinel setup --yes from the rustinel folder (.\rustinel.exe setup --yes on Windows). See Deploy on an endpoint.

Capture once, replay as your rules improve

sudo ./rustinel capture --output ~/captures/session.ndjson   # Ctrl-C when done
sudo chown -R "$USER" ~/captures
./rustinel replay ~/captures/session.ndjson
./rustinel replay ~/captures/session.ndjson --config candidate.toml

Replay needs no privileges and works across platforms: a Windows recording replays on Linux. See Test rules with replay.

Platform support

Platform Sensors Telemetry Status
Windows 10/11, Server 2016+ ETW + Windows Event Log Process, image load, network, file, registry, DNS, PowerShell, WMI, service, task, Security audit events Stable
Linux 5.8+ eBPF Process, network, file, DNS Stable
macOS 11+ Endpoint Security + /dev/bpf Process, file, network, DNS Experimental

Details: Platform coverage and Limitations.

Know the boundaries

Rustinel is built for endpoint monitoring, detection engineering, labs, and SIEM pipeline testing. It is not a replacement for a commercial EDR: it has no anti-tamper, no pre-execution blocking, and no management console. See the Security model.

Contribute

Bug reports, detection tests, and platform work are welcome. Tell us what you monitor and where you get stuck.

Contributing | Issues | Development guide | Roadmap

License

Apache 2.0.

Frequently asked questions

Is rustinel free to use?

rustinel is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does rustinel do?

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

What is rustinel written in?

rustinel is primarily written in Rust. Its source is publicly available at https://github.com/Karib0u/rustinel, and it has 501 GitHub stars.