
wazuh
Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Chronicle parser for CORELIGHT and related information.

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

Sigma rule for detecting scanning activity targeting CVE-2021-22005, enabling threat detection and log-based intrusion analysis.


Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.

GitHub mirror of the Linux Kernel's audit repository

Apache Real Time Logs Analyzer System

Detect Tactics, Techniques & Combat Threats