16 Repos
Platforms for aggregating, correlating, and analyzing security event data.
Explore 16 awesome GitHub repositories matching part of an awesome list · Security Logging and SIEM. Refine with filters or upvote what's useful.
Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in real time. By hooking into kernel-level interfaces, it tracks system-wide network activity and maps connection attempts to specific local processes, allowing users to explicitly permit or deny traffic on a per-application basis. The project distinguishes itself through its ability to manage security policies across multiple distributed nodes from a single, unified dashboard. This centralized management is secured via encrypted socket communication, enabling consistent rule en
Application firewall for GNU/Linux systems.
Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems
Translates generic detection signatures into specific queries for various SIEM platforms.
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Translates standardized security detection signatures into search queries for various SIEM and logging platforms.
Security Onion ist eine Plattform für Security Information and Event Management (SIEM) sowie eine Suite für die Netzwerksicherheitsüberwachung. Sie fungiert als Intrusion-Detection-System und Tool zur Netzwerktraffic-Analyse, um böswillige Aktivitäten und Eindringversuche durch signaturbasierte Erkennung und hostbasierte Überwachung zu identifizieren. Die Plattform integriert ein Security-Case-Management-System, um Untersuchungen durch die Nachverfolgung von Erkennungen und die Gruppierung zusammengehöriger Sicherheitsereignisse zu organisieren. Sie bietet Funktionen für Full-Packet-Capture, die Extraktion von Netzwerk-Metadaten sowie das Sammeln und Indizieren von Sicherheits-Logs aus verschiedenen Quellen. Das System deckt ein breites Spektrum an Sicherheitsoperationen ab, darunter die Untersuchung von Sicherheitsvorfällen, Threat-Hunting-Workflows und die Aggregation von Sicherheits-Logs. Es nutzt eine einheitliche Web-Konsole zur Analyse von Sicherheitsereignissen und Alerts und integriert künstliche Intelligenz zur Unterstützung bei der Untersuchung von Sicherheitsdaten.
Implements a full security information and event management platform for aggregating and analyzing security event data.
Adversary tradecraft detection, protection, and hunting
Tool for Windows kernel activity exploration and tracing.
Fast Incident Response
Cybersecurity incident management platform.
A network sniffer that logs all DNS server replies for use in a passive DNS setup
Tool for passive DNS collection and incident handling.
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
Serverless security lake platform for data ingestion and analysis.
Tenzir is the data pipeline engine for security teams.
Security data pipeline for high-volume telemetry.
🔥 A fully open source audit logs service and embeddable UI easily deployed to your own Kubernetes cluster. Brought to you by replicated.com and boxyhq.com 🚀
API for security and compliance audit logging.
Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.
Cloud-native data pipeline and transformation toolkit.
Open Source SIEM (Security Information and Event Management system).
Open-source SIEM system.
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Tool for converting Zeek logs to Elastic/OpenSearch.
TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel
Sigma rules converted for Terraform-based analytics.
Sigma Queries turned into KQL for Defender using pysigma - Automated
Sigma rules converted for KQL analysis.
Sigma Queries turned into SPL for Splunk Enterprise and Enterprise Security using pysigma - Automated
Sigma rules converted for SPL analysis.