
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Microsoft Threat Intelligence Security Tools

A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral…

Sigma detection rules for AI agent security monitoring

SQL powered operating system instrumentation, monitoring, and analytics.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Monitor your local neighbourhood's bluetooth activity

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

A Zeek OSPF packet analyzer based on Spicy.

Fingerprint SSH clients and servers.

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…