
tenzir
Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Microsoft Sentinel SIEM Log Source Analyzer

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!


YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Multi-threaded Windows event log forensics timeline generator and threat hunting tool with full Sigma rule support, producing CSV/JSON timelines for…

The Sigma command line interface based on pySigma

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

A repository to share publicly available Velociraptor detection content

Microsoft Threat Intelligence Security Tools

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and…

Self-contained SSH honeypot for capturing attacker interactions and turning them into structured security intelligence.

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.