
ntopng
Web-based Traffic and Cybersecurity Network Traffic Monitoring
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Dshell is a network forensic analysis framework.

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Automate the creation of a lab environment complete with security tooling and logging best practices

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

iOS Debugging Tool 🚀


Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Rapidly Search and Hunt through Windows Forensic Artefacts

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

the TCPdump network dissector

Investigate malicious Windows logon by visualizing and analyzing Windows event log

OS X Auditor is a free Mac OS X computer forensics tool

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

A repository of sysmon configuration modules