
loki
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Dshell is a network forensic analysis framework.

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…