
opensnitch
Interactive GNU/Linux application firewall that filters outbound connections, blocks ads and malware domains, manages system firewall rules via GUI,…

Interactive GNU/Linux application firewall that filters outbound connections, blocks ads and malware domains, manages system firewall rules via GUI,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

ZoneMinder is a free, open source Closed-circuit television software application developed for Linux which supports IP, USB and Analog cameras.

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

eBPF-based Security Observability and Runtime Enforcement

Automate the creation of a lab environment complete with security tooling and logging best practices

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Enterprise-grade honeypot system for detecting internal network breaches, external threats, and producing threat intelligence with 90+ service…

Canarytokens helps track activity and actions on your network

YARA signature and IOC database for my scanners and tools

Develop, validate, and publish SIEM detection rules for Elastic Security, with Python CLI tooling, KQL parsing, Kibana integration, and packaged…

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…