#1Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.
Kitploit recommended

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

SQL powered operating system instrumentation, monitoring, and analytics.

The easiest, and most secure way to access and protect all of your infrastructure.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Daemon to ban hosts that cause multiple authentication errors

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.


Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Arkime is an open source, large scale, full packet capturing, indexing, and database system.