Open-source endpoint detection. Three platforms. Your rules.
Run Sigma, YARA, and IOC detections on native Windows, Linux, and macOS telemetry.
Written in Rust, with local alerts and no cloud account required.
Bring your detection content, monitor your endpoints, and send alerts to the tools you already use.
Download | Documentation | Detection packs | Website
Endpoint detection should work with the platforms you run and the rules you already understand.
Rustinel brings native telemetry, established detection formats, and a common alert format into one open-source engine.
- Use Sigma and YARA rules. Detect behavior with Sigma, scan files and process memory with YARA, and match hash, IP, domain, and path indicators.
- Run across Windows, Linux, and macOS. Use one engine with a shared configuration model and normalized events. Sensors and detection coverage vary by platform.
- Keep control of your data. The live agent makes no outbound network connections. Alerts are local files you can inspect or forward yourself.
- Connect your existing tools. ECS 9.4.0 NDJSON output works with Elastic, Splunk, and other log pipelines.
- Test detections against recorded behavior. Capture telemetry once and replay it as your rules change, without repeating the activity.
- Inspect and extend the engine. Written in Rust and licensed under Apache 2.0.
Release archives include a binary, default configuration, and demo rules so you can verify detection before deploying a service.
Requires Linux 5.8+ with BTF support.
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel
sudo ./rustinel runRun in an elevated PowerShell:
irm https://rustinel.io/install.ps1 | iex
Set-Location rustinel
.\rustinel.exe runRequires the x64 Microsoft Visual C++ Redistributable. See Windows prerequisites.
macOS support is experimental. Complete the signing and Full Disk Access setup before starting the sensor.
curl -fsSL https://rustinel.io/install.sh | sh
cd rustinel
sudo ./rustinel runWhile Rustinel is running, open another terminal and run:
whoamiThe bundled demo rule detects the process. Find the alert in
logs/alerts.json.<date> inside the extracted release directory.
The demo rules verify that the pipeline works. For broader coverage, install a detection pack or add your own rules.
Prefer a manual installation? Browse the release archives or inspect the install scripts.
Stop the foreground agent with Ctrl-C, then run setup from the extracted release directory.
Linux and macOS:
sudo ./rustinel setup --yes
./rustinel doctorWindows, in an elevated PowerShell:
.\rustinel.exe setup --yes
.\rustinel.exe doctorSetup writes the managed configuration, installs the Essential rules pack, registers the native service, starts it, and checks its health.
Use --pack advanced for the larger pack or --no-start to register the service
without starting it.
| Platform | Service manager | Managed alert directory |
|---|---|---|
| Windows | SCM | C:\ProgramData\Rustinel\logs\ |
| Linux | systemd | /var/log/rustinel/ |
| macOS | launchd | /Library/Logs/Rustinel/ |
Rules and IOCs support hot reload. Optional process termination is available and disabled by default.
Configuration | Operations | SIEM examples
Use your own detection content or start with rustinel-rules, the official versioned Sigma, YARA, and IOC packs.
Packs are downloaded, SHA-256 verified, validated, and activated atomically. A failed download leaves the current rules in place.
Rule compatibility depends on the telemetry and fields available on each platform. A Windows rule does not automatically become a Linux detection.
We publish Sigma coverage measurements against a pinned SigmaHQ corpus, including missing collectors and unavailable fields. These measure whether rules have the data needed to fire, not whether they will detect every attack.
Rule authoring | Pack catalog | Coverage and gaps
Record endpoint activity, then evaluate the same events against new rules without repeating the activity or running sensors on your development machine.
From the release directory on Linux or macOS:
# Start recording, perform the activity, then press Ctrl-C.
sudo ./rustinel capture --output session.ndjson
# Evaluate the recording without elevated privileges.
./rustinel replay session.ndjson
# Compare another configuration.
./rustinel replay session.ndjson --config candidate.toml
# Export results for automated comparison.
./rustinel replay session.ndjson --output results.ndjsonOn Windows, use .\rustinel.exe and an elevated PowerShell for capture.
A Windows recording can replay on Linux or macOS. Replay uses the recorded platform for Sigma routing and produces reproducible results for the same recording and configuration.
Keep the recording and its .manifest.json sidecar together. Recordings contain
sensitive endpoint data, including command lines, paths, network destinations,
and user names.
Replay evaluates Sigma and IP, domain, and path IOC checks. YARA and hash checks are skipped because recordings contain events rather than file contents. Active response never runs during replay.
| Platform | Sensors | Telemetry | Status |
|---|---|---|---|
| Windows 10/11, Server 2016+ | ETW + Windows Event Log | Process, image load, network, file, registry, DNS, PowerShell, WMI, service, task, selected Security events | Stable |
| Linux 5.8+ with BTF | eBPF | Process, network, file, DNS | Stable |
| macOS 11+ | Endpoint Security + /dev/bpf |
Process, file, network, DNS | Experimental |
Windows has the broadest coverage today. See requirements and limitations for platform-specific details.
The live agent collects and evaluates telemetry locally. It does not send telemetry home or require a vendor account.
Installers download published releases. setup, rules list, and rules install
fetch the rules catalog; setup and rule installation also download packs.
Alerts remain on the endpoint unless you forward them through your own pipeline.
Rustinel supports endpoint monitoring, detection engineering, security labs, and SIEM pipeline validation.
It is not a drop-in replacement for a mature commercial EDR. It does not provide kernel-level self-protection, pre-execution blocking, anti-tamper guarantees, or managed response. A sufficiently privileged attacker may interfere with user-mode telemetry.
Read the current limitations when evaluating it for your environment.
Help improve platform coverage, test detections, report bugs, or make setup easier.
If you use Rustinel, tell us what you monitor, which rules matter to you, and where you get stuck. Real deployment feedback helps guide the project.

