
How-To-Secure-A-Linux-Server
Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

SQL powered operating system instrumentation, monitoring, and analytics.

The easiest, and most secure way to access and protect all of your infrastructure.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Daemon to ban hosts that cause multiple authentication errors

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.


Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

A repository of sysmon configuration modules

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Automate the creation of a lab environment complete with security tooling and logging best practices
