EvilBit Labs
Operator-focused Security Tooling
We build operator-focused security tools that work offline, on purpose.
Trusted for Enterprise & Open Source
Flagship Products
What We Build
DaemonEye
High-performance security process monitoring system with audit-grade integrity. Detect process anomalies, hollowing attacks, and suspicious behavior across your infrastructure.
- Real-time process monitoring with <5% system overhead
- Cross-platform security monitoring for Linux, macOS, and Windows
- SQL-based custom detection rules with flexible anomaly detection
dbsurveyor
Fast, offline database schema discovery and sampling. Understand unfamiliar databases quickly with portable reports.
- Schema + sample extraction with throttle control
- Portable outputs with optional compression and AES-GCM encryption
- Markdown/JSON reports and SQL reconstruction
opnDossier
v1.4.0Readable reports from OPNsense configs. Turns OPNsense config.xml files into clear, operator-ready documentation with optional audit reporting.
- Convert: structured Markdown/JSON/YAML (summary or comprehensive)
- Display: themed terminal rendering with syntax highlighting
- Audit: standard/blue/red reports with findings and recommendations
Community Tools
Open Source
libmagic-rs
A pure-Rust replacement of libmagic, the library behind the file command
token-privilege
Safe Rust wrapper for Windows process token privilege and elevation detection.
mmap-guard
Safe, guarded memory-mapped file I/O for Rust.
Stringy
Format-aware alternative to strings. Uses binary format intelligence to find useful strings where others see noise.
gold_digger
Gold Digger is a Rust-based query tool for MySQL and MariaDB systems, designed for routine collection and automation of database queries using environmental variables.