Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Sentora — An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations. | Kitploit
Outils/GitHubGitHub/d3vhex/sentora
Vulnerability ScannersThreat IntelligenceIntrusion DetectionIncident ResponseAI SecurityLog Analysis
GitHubd3vhex/sentora

Sentora

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.

Voir le dépôt
10101il y a 15 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Sentora Community Edition

License: AGPL v3 Python 3.10+ Built with Sanic

Self-hosted security stack for small/mid teams that don't have a dedicated SOC. Drop an agent on each endpoint, point them at the server, and you get SIEM logs, file integrity, package vulnerabilities, an OpenSearch-powered log explorer, autonomous AI triage and a SOAR playbook engine, all in one docker compose up.

The "AI" part is a locally-running Ollama model (default llama3.2:3b). Logs never leave the box; there's no OpenAI key, no Anthropic key, no phone-home. If you want a smarter model and have the RAM, swap it in .env.

Dashboard


What it actually does

  • Collects telemetry from Windows and Linux agents over a single TCP channel. SIEM events, alerts, FIM, packages, network connections, open ports, Docker activity, screen frames.

  • Detects with Sigma rules, on the endpoint. 43 rules covering 47 MITRE ATT&CK techniques ship in conf/sigma/builtin/; drop community rulesets in beside them. Sigma matches named fields rather than text, so Image|endswith: '\vssadmin.exe' cannot be defeated by the word "vssadmin" appearing in an unrelated message — and CommandLine|utf16le|base64offset|contains reads inside a base64 -EncodedCommand payload, where the plaintext command line shows only the wrapper. Measured on the eval corpus: 9 of 10 attacks caught by Sigma alone, 0 of 9 hard negatives falsely flagged. This layer is deterministic and keeps working when the model is unavailable.

  • Correlates across events, which no per-event rule can do. A single failed logon is routine; five accounts failing from one source in forty seconds is a password spray, and looking at any one of those five events will never tell you that. Covers spray, brute force, a success arriving after repeated failures, and bursts of account creation or service installs — on both platforms, from Windows event IDs or from parsed auth.log lines.

    Runs at two vantage points, because they see different attacks. Per host on the agent, where an attack against one machine is visible in full. And across hosts in the ingest path, where a spray walked one failure at a time over fifty machines shows up — no single agent sees more than one event, and that is the more competent attack, since spraying wide and shallow stays under both per-account lockout and per-host thresholds.

    Total coverage with Sigma: 51 techniques. Every window fires once rather than once per event, and every counter is bounded — a counter keyed on an attacker-supplied username is a memory exhaustion primitive, not a detection.

  • Maps detections to MITRE ATT&CK, from the rules themselves. Rules carry tags: attack.t1490, so there is no hand-kept mapping table to go stale. The coverage page separates three states a single "coverage %" would hide: covered and seen, covered and quiet, and not covered at all — the last being the only one where the console's silence means nothing.

  • Triages every event with a local LLM. Three workers run in parallel: one watches every incoming event in real time, one runs operator-driven deep scans, and one decides whether to take a defensive action (BLOCK_IP, ISOLATE_HOST, KILL_PROCESS, etc.).

  • Shadow mode for the defensive worker. Flip AI_SHADOW_MODE=1 and every autonomous verdict is staged for human approval in the SOAR Hub instead of being dispatched. Useful for tuning the model on real traffic before letting it act on its own.

  • Indexes everything in OpenSearch so you can grep your fleet with fuzzy / exact / starts-with queries from one place.

  • Runs SOAR playbooks built in a small visual editor with multi-step, per-node result tracking, can be triggered manually or by AI verdict.

  • Vulnerability scans every agent's installed packages against OSV (online or via an internal mirror).

  • Pulls threat-intel feeds from abuse.ch (Feodo, ThreatFox, URLhaus) into a local indicator table, with staleness pruning and an air-gap switch.

  • Validates agent configs before pushing them. YAML parse, structural shape and regex compilation — an invalid regex is valid YAML and silently disables the rule containing it.

  • Built-in remote desktop via WebSocket JPEG streaming, no separate VNC install needed on the endpoint.

What it looks like

The sidebar groups everything into three sections: telemetry (dashboard, agents, alerts, assets, FIM, logs, AI), automation response (defensive actions, playbooks, automation rules), and administration.

Sidebar navigation

Per-agent view

Each enrolled agent has its own page with twelve tabs. The overview shows live resource meters, the most recent SIEM logs, agent metadata and a threat summary:

Agent overview

Alerts are everything the agent's own correlation rules already flagged. Severity-coloured, filterable, searchable:

Agent alerts

The AI Analysis tab is the operator-facing side of the local LLM. Manual and automatic scans both land here. Each insight carries a verdict chip, confidence, MITRE indicators (when the model returns them), IOCs, next steps, and a View Source button that opens the exact log row the AI looked at:

AI analysis

Asset inventory

Hardware, software, and network sockets per agent. Hardware tab lists every PnP device, software lists installed packages, network lists every TCP/UDP socket with its owning process:

Asset inventory: hardware

Asset inventory: network

Log Explorer

Cross-agent search backed by OpenSearch. Pick an agent, pick a dataset (SIEM events, security alerts, process events, network, FIM, audit logs), and search. There's also a button to open OpenSearch Dashboards (Kibana fork) for power users:

Log Explorer

Audit logs

Every login attempt against the platform itself, both local and LDAP, with result, source IP, and timestamp. Useful when someone is in the "who-logged-in-when" mood:

Télécharger l’outil