
graylog2-server
Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Daemon to ban hosts that cause multiple authentication errors

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/


YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

GitHub mirror of the Linux Kernel's audit repository

The Sigma command line interface based on pySigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

A Software as a Service (SaaS) log collection framework.


Detect Tactics, Techniques & Combat Threats

Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file…