
wazuh
Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

AI-driven endpoint governance platform that monitors software usage, applies deterministic policy-based risk classification, and generates structured…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Local, monitor-first observability for AI agents: processes, file activity, TCP endpoints and attribution evidence. Windows primary; macOS/Linux…

Open source entropy based invalid traffic detection and pre-bid filtering.

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Open-source IoT Platform - Device management, data collection, processing and visualization.

A python library for user-friendly forecasting and anomaly detection on time series.

Linux system-call monitor using ptrace to trace file, process, network, and memory activity, with namespace isolation and machine learning…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Streaming machine learning library for incremental learning on data streams, providing online estimators, drift and anomaly detection, pipelines,…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

ML-driven threat detection and continuous monitoring platform built for federal zero trust architectures.