awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

16 Repos

Awesome GitHub RepositoriesSecurity Logging and SIEM

Platforms for aggregating, correlating, and analyzing security event data.

Explore 16 awesome GitHub repositories matching part of an awesome list · Security Logging and SIEM. Refine with filters or upvote what's useful.

Awesome Security Logging and SIEM GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • evilsocket/opensnitchAvatar von evilsocket

    evilsocket/opensnitch

    12,899Auf GitHub ansehen↗

    Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in real time. By hooking into kernel-level interfaces, it tracks system-wide network activity and maps connection attempts to specific local processes, allowing users to explicitly permit or deny traffic on a per-application basis. The project distinguishes itself through its ability to manage security policies across multiple distributed nodes from a single, unified dashboard. This centralized management is secured via encrypted socket communication, enabling consistent rule en

    Application firewall for GNU/Linux systems.

    Pythonapplication-firewalldata-breachfirewall
    Auf GitHub ansehen↗12,899
  • neo23x0/sigmaAvatar von Neo23x0

    Neo23x0/sigma

    10,591Auf GitHub ansehen↗

    Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems

    Translates generic detection signatures into specific queries for various SIEM platforms.

    Python
    Auf GitHub ansehen↗10,591
  • sigmahq/sigmaAvatar von SigmaHQ

    SigmaHQ/sigma

    10,136Auf GitHub ansehen↗

    Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that

    Translates standardized security detection signatures into search queries for various SIEM and logging platforms.

    Pythonelasticsearchidslogging
    Auf GitHub ansehen↗10,136
  • security-onion-solutions/securityonionAvatar von Security-Onion-Solutions

    Security-Onion-Solutions/securityonion

    4,661Auf GitHub ansehen↗

    Security Onion ist eine Plattform für Security Information and Event Management (SIEM) sowie eine Suite für die Netzwerksicherheitsüberwachung. Sie fungiert als Intrusion-Detection-System und Tool zur Netzwerktraffic-Analyse, um böswillige Aktivitäten und Eindringversuche durch signaturbasierte Erkennung und hostbasierte Überwachung zu identifizieren. Die Plattform integriert ein Security-Case-Management-System, um Untersuchungen durch die Nachverfolgung von Erkennungen und die Gruppierung zusammengehöriger Sicherheitsereignisse zu organisieren. Sie bietet Funktionen für Full-Packet-Capture, die Extraktion von Netzwerk-Metadaten sowie das Sammeln und Indizieren von Sicherheits-Logs aus verschiedenen Quellen. Das System deckt ein breites Spektrum an Sicherheitsoperationen ab, darunter die Untersuchung von Sicherheitsvorfällen, Threat-Hunting-Workflows und die Aggregation von Sicherheits-Logs. Es nutzt eine einheitliche Web-Konsole zur Analyse von Sicherheitsereignissen und Alerts und integriert künstliche Intelligenz zur Unterstützung bei der Untersuchung von Sicherheitsdaten.

    Implements a full security information and event management platform for aggregating and analyzing security event data.

    Shell
    Auf GitHub ansehen↗4,661
  • rabbitstack/fibratusAvatar von rabbitstack

    rabbitstack/fibratus

    2,493Auf GitHub ansehen↗

    Adversary tradecraft detection, protection, and hunting

    Tool for Windows kernel activity exploration and tracing.

    Goadversaryblueteamedr
    Auf GitHub ansehen↗2,493
  • certsocietegenerale/firAvatar von certsocietegenerale

    certsocietegenerale/FIR

    2,009Auf GitHub ansehen↗

    Fast Incident Response

    Cybersecurity incident management platform.

    JavaScript
    Auf GitHub ansehen↗2,009
  • gamelinux/passivednsAvatar von gamelinux

    gamelinux/passivedns

    1,737Auf GitHub ansehen↗

    A network sniffer that logs all DNS server replies for use in a passive DNS setup

    Tool for passive DNS collection and incident handling.

    C
    Auf GitHub ansehen↗1,737
  • matanolabs/matanoAvatar von matanolabs

    matanolabs/matano

    1,676Auf GitHub ansehen↗

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

    Serverless security lake platform for data ingestion and analysis.

    Rust
    Auf GitHub ansehen↗1,676
  • tenzir/vastAvatar von tenzir

    tenzir/vast

    742Auf GitHub ansehen↗

    Tenzir is the data pipeline engine for security teams.

    Security data pipeline for high-volume telemetry.

    C++
    Auf GitHub ansehen↗742
  • retracedhq/retracedAvatar von retracedhq

    retracedhq/retraced

    445Auf GitHub ansehen↗

    🔥 A fully open source audit logs service and embeddable UI easily deployed to your own Kubernetes cluster. Brought to you by replicated.com and boxyhq.com 🚀

    API for security and compliance audit logging.

    TypeScript
    Auf GitHub ansehen↗445
  • brexhq/substationAvatar von brexhq

    brexhq/substation

    402Auf GitHub ansehen↗

    Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.

    Cloud-native data pipeline and transformation toolkit.

    Go
    Auf GitHub ansehen↗402
  • dogoncouch/logespAvatar von dogoncouch

    dogoncouch/LogESP

    219Auf GitHub ansehen↗

    Open Source SIEM (Security Information and Event Management system).

    Open-source SIEM system.

    Python
    Auf GitHub ansehen↗219
  • corelight/zeek2esAvatar von corelight

    corelight/zeek2es

    40Auf GitHub ansehen↗

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Tool for converting Zeek logs to Elastic/OpenSearch.

    Python
    Auf GitHub ansehen↗40
  • khadinxc/terrasigmaAvatar von Khadinxc

    Khadinxc/TerraSigma

    3Auf GitHub ansehen↗

    TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel

    Sigma rules converted for Terraform-based analytics.

    HCL
    Auf GitHub ansehen↗3
  • khadinxc/sigma2kqlAvatar von Khadinxc

    Khadinxc/Sigma2KQL

    3Auf GitHub ansehen↗

    Sigma Queries turned into KQL for Defender using pysigma - Automated

    Sigma rules converted for KQL analysis.

    Python
    Auf GitHub ansehen↗3
  • khadinxc/sigma2splAvatar von Khadinxc

    Khadinxc/Sigma2SPL

    0Auf GitHub ansehen↗

    Sigma Queries turned into SPL for Splunk Enterprise and Enterprise Security using pysigma - Automated

    Sigma rules converted for SPL analysis.

    Python
    Auf GitHub ansehen↗0
  1. Home
  2. Part of an Awesome List
  3. Databases & Data
  4. Security Logging and SIEM

Unter-Tags erkunden

  • SIEM Rule ConvertersUtilities that translate standardized security rules into search queries for specific SIEM platforms. **Distinct from Security Logging and SIEM:** Focuses on the conversion of rules into queries, whereas Security Logging and SIEM refers to the platforms themselves.