
ntopng
Web-based Traffic and Cybersecurity Network Traffic Monitoring

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…


Collection of Google Cloud solution examples and operational utilities for audit log monitoring, DLP de-identification, encryption key management,…

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.

Microsoft Threat Intelligence Security Tools

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Open source log management platform for centralized log aggregation, real-time analysis, and security event monitoring with customizable dashboards…

Enrich the conn.log with EDR data

A machine learning toolkit for log parsing [ICSE'19, DSN'16]

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to…