
matano
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

The easiest, and most secure way to access and protect all of your infrastructure.

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management


Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

Distributed & real time digital forensics at the speed of the cloud

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

PowerShell module for Office 365 and Azure log collection

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Zeek package for tracking long connections to report them before they have completed.

Burp proxy text log converter to CSV and SQLLite

Bro analyzer that detects Google's QUIC protocol

A repository to release detection rules to the public