
Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks, and account takeover via a rule engine and audit trails.
tirreno is a security framework.
tirreno [tir.ˈrɛ.no] helps understand, monitor, and protect your product from threats, fraud, and abuse. While classic cybersecurity focuses on infrastructure and network perimeter, most breaches occur through compromised accounts and application logic abuse that bypasses firewalls, SIEM, WAFs, and other defenses. tirreno detects threats where they actually happen: inside your product.
tirreno is a hand-written, few-dependency, "low-tech" PHP/PostgreSQL application. After a straightforward five-minute installation, you can ingest events through API calls and immediately access a dashboard.
Account takeover Credential stuffing Content spam Account registration Fraud prevention Insider threat
Bot detection Dormant account Multi-accounting Promo abuse API protection High-risk regions
Check out the live demo at play.tirreno.com (admin/tirreno).
PDO_PGSQL, cURLApache with mod_rewrite and mod_headers enabledTo run tirreno within a Docker container you may use command below:
curl -sL tirreno.com/t.yml | docker compose -f - up -d
Continue with step 4 of Quickstart.
http://localhost:8585/install/index.php in a browser to launch the installation process.install/ directory and its contents.http://localhost:8585/signup/ in a browser to create an administrator account.crontab -e command or by editing the /var/spool/cron/your-web-server file:*/10 * * * * /usr/bin/php /absolute/path/to/tirreno/index.php /cron
Click here to launch heroku deployment.
tirreno is published at Packagist and could be installed with Composer:
composer create-project tirreno/tirreno
or could be pulled into an existing project:
composer require tirreno/tirreno
tirreno('…')` is tirreno's built-in API. It gives your own code the same building blocks the console uses: the current request and page, the ingested data, the rule engine, the tirreno('queries') builder, logging, and utilities. Use it to customize tirreno. The examples below show custom sections built with this API.
See the User guide for details on how to use tirreno, Developers documentation to customize your integration, Admin documentation for installation, maintenance and updates.
tirreno is an open-source framework for building sovereign security, compliance and fraud prevention applications.
The project started as a proprietary system in 2021 and was open-sourced (AGPL) in December 2024.
We solve real people's challenges through love in ascétique code and open technologies. tirreno is not VC-motivated. Our inspiration comes from the daily threats posed by organized cybercriminals, driving us to reimagine the place of security in modern organizations.
Tyrrhenian people may have lived in Tuscany and eastern Switzerland as far back as 800 BC. The term "Tyrrhenian" became more commonly associated with the Etruscans, and it is from them that the Tyrrhenian Sea derives its name, which is still in use today.
According to historical sources, Tyrrhenian people were the first to use trumpets for signaling about coming threats, which was later adopted by Greek and Roman military forces.