awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Cyb3rWard0g avatar

Cyb3rWard0g/HELK

0
View on GitHub↗
3,926 stars·689 forks·Jupyter Notebook·GPL-3.0·12 views

HELK

HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data.

The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and anomalies through graph-based relationship mapping.

The platform covers a broad surface of security operations, including SIEM deployment, log aggregation, and indexing-based log search. It utilizes a container-based infrastructure to deploy the full toolset for security log analysis and threat hunting.

Features

  • SIEM Deployments - Sets up a centralized system for collecting, indexing, and visualizing security events across an organization.
  • Security Data Science Suites - Integrates interactive notebooks and distributed processing tools for running machine learning on security logs.
  • Security Log Analytics - Runs machine learning and graph analytics on security data using notebooks and distributed processing.
  • Log Indexing Systems - Organizes unstructured security logs into a searchable index for fast retrieval and complex query execution.
  • Security Analysis Platforms - Provides a security-focused deployment of the ELK stack for threat hunting and log analysis.
  • Security Data Science - Utilizes machine learning and graph analytics on security datasets to discover hidden attack patterns and anomalies.
  • Security Relationship Mappings - Maps connections between security entities to identify hidden attack patterns and lateral movement during investigations.
  • Interactive Threat Hunt Notebooks - Integrates interactive computational notebooks for running analytics and validation queries during exploratory threat hunting.
  • Threat Hunting Infrastructures - Deploys a pre-configured security environment via containers to quickly start analyzing network and host data.
  • Containerized SIEM Platforms - Provides a pre-configured set of Docker containers that deploy a full security information and event management stack.
  • Log Analyzers - Hunts for threats and investigates logs using a specialized stack of indexing, visualization, and ingestion tools.
  • Log Analysis - Searches and investigates system logs using the ELK stack to identify threats and suspicious activity.
  • Log Aggregation Pipelines - Collects and transforms raw security events through an ingestion pipeline before indexing them for search.
  • Distributed Data Processing - Spreads heavy machine learning and graph analytic workloads across multiple nodes to handle large security datasets.
  • Container Deployment - Provides a containerized deployment of the entire security toolset to ensure consistent environment setup.
  • Deployment Infrastructure - Provides the underlying containerized technical stack required to host the security analysis environment.
  • Detection Labs - Pre-configured ELK stack for advanced threat hunting analytics.
  • Forensics and Incident Response - Hunting ELK stack with advanced analytic capabilities.
  • Detection and Hunting Tools - An advanced hunting platform based on the Elastic stack.
  • Incident Response Frameworks - Integrated platform for threat hunting and data analysis.
  • Threat Hunting Operations - Stack for threat hunting using elasticsearch and analytics integrations.

Star history

Star history chart for cyb3rward0g/helkStar history chart for cyb3rward0g/helk

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does cyb3rward0g/helk do?

HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data.

What are the main features of cyb3rward0g/helk?

The main features of cyb3rward0g/helk are: SIEM Deployments, Security Data Science Suites, Security Log Analytics, Log Indexing Systems, Security Analysis Platforms, Security Data Science, Security Relationship Mappings, Interactive Threat Hunt Notebooks.

Which projects share features with cyb3rward0g/helk?

Projects with overlapping indexed features include: graylog2/graylog2-server — Graylog2-server is an open-source centralized log management system and aggregator. It functions as a log analysis… tencent/gt — GT is an on-device mobile debugging tool designed to capture network packets, analyze system logs, and profile… awesome-selfhosted/awesome-selfhosted — This project is a community-curated directory of open-source software designed for deployment in private server… highlight/highlight — Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… comodosecurity/openedr — OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to…

Projects sharing features with HELK

These projects share indexed features with HELK. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • tencent/gtTencent avatar

    Tencent/GT

    4,407View on GitHub↗

    GT is an on-device mobile debugging tool designed to capture network packets, analyze system logs, and profile hardware performance directly on a smartphone. It provides a portable suite of utilities for identifying software bugs and processing bottlenecks without requiring a connection to a host computer. The project features a plugin-based debugging framework that allows for the development of custom functional extensions to implement project-specific debugging logic. It also enables real-time parameter tuning and injection, allowing internal application settings to be modified during execu

    Java
    View on GitHub↗4,407
  • graylog2/graylog2-serverGraylog2 avatar

    Graylog2/graylog2-server

    8,066View on GitHub↗

    Graylog2-server is an open-source centralized log management system and aggregator. It functions as a log analysis platform designed to collect, index, and analyze log data from multiple sources within a centralized searchable index. The system provides capabilities for enterprise log aggregation and infrastructure monitoring. It enables the gathering of logs from various servers and applications to facilitate log data analysis and root cause troubleshooting across a network. The platform utilizes a distributed indexing pipeline and message-queue based ingestion to handle log streams. It inc

    Javaamqpgelfgraylog
    View on GitHub↗8,066
  • awesome-selfhosted/awesome-selfhostedawesome-selfhosted avatar

    awesome-selfhosted/awesome-selfhosted

    299,516View on GitHub↗

    This project is a community-curated directory of open-source software designed for deployment in private server environments and home labs. It serves as a comprehensive resource for discovering independent, self-hosted alternatives to mainstream cloud services, enabling users to maintain full data ownership and control over their digital infrastructure. The directory is structured through a hierarchical taxonomy that organizes a vast collection of applications into logical categories, ranging from media management and data analytics to private communication and team productivity tools. It dis

    awesomeawesome-listcloud
    View on GitHub↗299,516
  • highlight/highlighthighlight avatar

    highlight/highlight

    9,303View on GitHub↗

    Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed traces to provide a unified view of application health. It functions as a distributed tracing system, an error monitoring service, and a session replay tool. The platform is available as a dockerized monitoring stack for self-hosted deployments on Linux. It distinguishes itself by combining backend observability with a visual recording system that captures document object model changes and network requests to replay user interactions. The system covers several core capability

    TypeScript
    View on GitHub↗9,303
Compare all 30 related projects→