
wazuh
Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

A machine learning toolkit for log parsing [ICSE'19, DSN'16]

Automated cloud security auditing tool that detects AK/SK credential misuse by periodically auditing cloud platform logs using anomaly detection,…


Web-based Traffic and Cybersecurity Network Traffic Monitoring

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

Microsoft Threat Intelligence Security Tools

A machine learning toolkit for log-based anomaly detection [ISSRE'16]

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

A deep learning toolkit for log-based anomaly detection

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Enrich the conn.log with EDR data

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.