How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Open Source SIEM (Security Information and Event Management system).
TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel
The main features of khadinxc/terrasigma are: Security Logging and SIEM.
Open-source alternatives to khadinxc/terrasigma include: security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… corelight/zeek2es — A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON… dogoncouch/logesp — Open Source SIEM (Security Information and Event Management system). evilsocket/opensnitch — Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in… gamelinux/passivedns — A network sniffer that logs all DNS server replies for use in a passive DNS setup. certsocietegenerale/fir — Fast Incident Response.