
ntopng
Web-based Traffic and Cybersecurity Network Traffic Monitoring

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Daemon to ban hosts that cause multiple authentication errors

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…


YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Corelight or Zeek Elastic Common Schema Templates

Mapping Corelight or Zeek data to Elastic Common Schema fields


Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

Enhanced SSH client with TUI — manage connections, keys, and sessions

TheLightScope

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…