awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to airbnb/streamalert

Open-source alternatives to Streamalert

30 open-source projects similar to airbnb/streamalert, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Streamalert alternative.

  • jonrau1/electriceyejonrau1 avatar

    jonrau1/ElectricEye

    1,043View on GitHub↗

    ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

    Pythonasset-managementattack-surface-managementaws
    View on GitHub↗1,043
  • cloudquery/cloudquerycloudquery avatar

    cloudquery/cloudquery

    6,438View on GitHub↗

    CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses. The system distinguishes itself by transforming complex, nested cloud API responses into flat relational tables, enabling the use of standard SQL for asset querying and analysis. It employs a modular plugin system for data ex

    Goairbyteattack-surface-managementaws
    View on GitHub↗6,438
  • brexhq/substationbrexhq avatar

    brexhq/substation

    402View on GitHub↗

    Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.

    Go
    View on GitHub↗402
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
  • microsoft/security-101microsoft avatar

    microsoft/Security-101

    6,203View on GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    View on GitHub↗6,203
  • quay/clairquay avatar

    quay/clair

    11,012View on GitHub↗

    Clair is a container image vulnerability scanner and security analyzer. It performs static analysis of container images by matching package contents against vulnerability databases to identify security risks across different package formats and architectures. The project functions as both an image indexer and a vulnerability database manager. It processes container layers into intermediate representations to enable fast security lookups and synchronizes security metadata from multiple external sources to maintain a local registry. Capability areas include continuous security monitoring, whic

    Goclaircontainersdocker
    View on GitHub↗11,012
  • dowjones/hammerdowjones avatar

    dowjones/hammer

    450View on GitHub↗

    Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)

    Python
    View on GitHub↗450
  • bad-antics/nullsec-logreaperbad-antics avatar

    bad-antics/nullsec-logreaper

    80View on GitHub↗

    🪓 High-Speed Log Analysis & Forensics Tool - Part of NullSec Toolkit

    C
    View on GitHub↗80
  • airtai/faststreamairtai avatar

    airtai/faststream

    5,234View on GitHub↗

    FastStream is an asynchronous Python framework designed for building event-driven microservices. It provides a unified abstraction layer for interacting with various message brokers, enabling developers to manage event production and consumption through a consistent interface while maintaining access to native provider-specific features. The framework centers on a decorator-based routing model that binds application logic directly to broker topics, supported by a built-in dependency injection container that resolves resources at runtime. The framework distinguishes itself through its deep int

    Python
    View on GitHub↗5,234
  • countercept/chainsawcountercept avatar

    countercept/chainsaw

    3,567View on GitHub↗

    Rapidly Search and Hunt through Windows Forensic Artefacts

    Rust
    View on GitHub↗3,567
  • dogoncouch/logdissectdogoncouch avatar

    dogoncouch/logdissect

    160View on GitHub↗

    CLI utility and Python module for analyzing log files and other data.

    Python
    View on GitHub↗160
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
  • duo-labs/cloudmapperduo-labs avatar

    duo-labs/cloudmapper

    6,259View on GitHub↗
    JavaScriptawscytoscapediagram
    View on GitHub↗6,259
  • hortonworks/streamlinehortonworks avatar

    hortonworks/streamline

    167View on GitHub↗

    StreamLine - Streaming Analytics

    Java
    View on GitHub↗167
  • btkrausen/awsbtkrausen avatar

    btkrausen/AWS

    75View on GitHub↗
    View on GitHub↗75
  • apache/kafkaapache avatar

    apache/kafka

    32,846View on GitHub↗

    Kafka is a distributed event streaming platform designed for capturing, storing, and processing real-time data streams across interconnected nodes. It functions as a distributed commit log, providing a fault-tolerant storage mechanism that records state changes sequentially to ensure data consistency and durability across distributed environments. The platform distinguishes itself through a partitioned commit log architecture that enables horizontal scaling and parallel processing of data streams. It integrates a stream processing engine for continuous transformations and aggregations, while

    Javakafkascala
    View on GitHub↗32,846
  • gebalamariusz/cloud-auditgebalamariusz avatar

    gebalamariusz/cloud-audit

    60View on GitHub↗

    Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes.

    Python
    View on GitHub↗60
  • globaldatanet/aws-firewall-factoryglobaldatanet avatar

    globaldatanet/aws-firewall-factory

    256View on GitHub↗

    Enhance the security of your web applications effortlessly with AWS Firewall Factory. Safeguard your valuable assets through seamless WAF deployment, updates, and staging, all centrally managed with AWS Firewall Manager.

    TypeScript
    View on GitHub↗256
  • google/mediapipegoogle avatar

    google/mediapipe

    35,673View on GitHub↗

    MediaPipe is a cross-platform machine learning framework designed for building and deploying pipelines that process live and streaming media. It provides a system for connecting processing components into custom machine learning chains to analyze real-time audio and video streams. The framework includes a suite of pre-trained models for tasks such as hand, face, and pose tracking, along with tools for retraining and customizing these models with specific datasets. It also features a dedicated benchmarker for measuring the execution speed and accuracy of machine learning models directly within

    C++
    View on GitHub↗35,673
  • functional-streams-for-scala/fs2functional-streams-for-scala avatar

    functional-streams-for-scala/fs2

    2,447View on GitHub↗

    Compositional, streaming I/O library for Scala

    Scala
    View on GitHub↗2,447
  • iagcl/watchmeniagcl avatar

    iagcl/watchmen

    177View on GitHub↗

    (Not maintained anymore) Watchmen - AWS account compliance using centrally managed Config Rules

    Python
    View on GitHub↗177
  • jeffail/benthosJeffail avatar

    Jeffail/benthos

    8,681View on GitHub↗

    Benthos is a declarative stream processor and data integration pipeline used to route, transform, and filter information between disparate services. It functions as an at-least-once message broker and change data capture engine, using a transaction model to guarantee message delivery despite system crashes or server faults. The system is defined by an observability-first approach, featuring built-in HTTP health probes, performance metrics export, and distributed request flow tracing. It utilizes a plugin architecture that allows the core engine to be extended with custom binaries for new inpu

    Go
    View on GitHub↗8,681
  • jensvoid/lorgjensvoid avatar

    jensvoid/lorg

    214View on GitHub↗

    Apache Logfile Security Analyzer

    HTML
    View on GitHub↗214
  • bridgecrewio/yorbridgecrewio avatar

    bridgecrewio/yor

    927View on GitHub↗

    Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified resource which created it.

    Go
    View on GitHub↗927
  • jonrau1/syntheticsunjonrau1 avatar

    jonrau1/SyntheticSun

    82View on GitHub↗

    SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, managed AWS security services and, serverless technologies to continuously prevent, detect and respond to threats.

    Python
    View on GitHub↗82
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
  • jpcertcc/sysmonsearchJPCERTCC avatar

    JPCERTCC/SysmonSearch

    431View on GitHub↗

    Investigate suspicious activity by visualizing Sysmon's event log

    JavaScript
    View on GitHub↗431
  • jtblin/kube2iamjtblin avatar

    jtblin/kube2iam

    2,040View on GitHub↗

    kube2iam provides different AWS IAM roles for pods running on Kubernetes

    HTML
    View on GitHub↗2,040
  • duo-labs/parliamentduo-labs avatar

    duo-labs/parliament

    1,117View on GitHub↗

    AWS IAM linting library

    Python
    View on GitHub↗1,117