
goaccess
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Digital forensics suite for DJI drones that parses telemetry files, extracts hidden data via steganography, visualizes flight paths, and detects…

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

A network packet forensics tool for SSH

Enumerate various traits from Windows processes as an aid to threat hunting

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Open-source EDR for AI agents. Monitor processes, files, network, and behavior of autonomous AI agents.

Serverless AWS security automation framework that ingests threat intelligence, applies ML-based anomaly detection (RCF, IP Insights), and enriches…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection

Zeek package for tracking long connections to report them before they have completed.

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Sigma detection rules for AI agent security monitoring