
ntopng
Web-based Traffic and Cybersecurity Network Traffic Monitoring

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…

Daemon to ban hosts that cause multiple authentication errors

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


GitHub mirror of the Linux Kernel's audit repository

The Sigma command line interface based on pySigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

A repository to share publicly available Velociraptor detection content

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.