awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
ComodoSecurity avatar

ComodoSecurity/openedr

0
View on GitHub↗
2,603 stars·504 forks·C++·other·48 views

Openedr

OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity.

The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks.

The platform provides capabilities for monitoring system API calls, file and registry access, and network traffic. It incorporates security breach detection and alerting through customizable telemetry filtering rules and policy configurations. To maintain system integrity, it employs a dedicated self-protection provider to prevent unauthorized modifications to monitoring agents and configurations.

Features

  • Endpoint Detection and Response - Provides a comprehensive endpoint detection and response platform for monitoring system activity and detecting security breaches.
  • Intrusion Detection Systems - Implements a host-based intrusion detection system that monitors system activity and applies alerting policies to detect security breaches.
  • Telemetry Collection and Aggregation - Gathers detailed file, device, and system activity data to provide granular visibility into environment behavior.
  • Intrusion Detection Systems - Functions as a host-based intrusion detection system by tracking API calls and kernel activity on Windows endpoints.
  • Event Callbacks - Implements kernel-level callbacks to intercept process and thread lifecycle changes for security telemetry collection.
  • User-Mode API Hooking Frameworks - Implements user-mode API hooking to intercept function calls in running processes for activity tracking.
  • Process Hierarchy Tracking - Tracks parent-child process relationships and lineage within the kernel to reconstruct attack timelines.
  • Attack Root Cause Analysis - Provides a security event visualizer that maps process lineage to facilitate the root-cause analysis of system compromises.
  • Runtime Threat Detection - Evaluates real-time system activity against security rules to identify malicious patterns and breach indicators.
  • Endpoint Activity Monitoring - Tracks process creation, deletion, and API calls via kernel callbacks and library injection to detect malicious behavior.
  • System Registry Monitoring - Provides hooks to record modifications and unauthorized changes to both the file system and system registries.
  • Log Aggregation Pipelines - Includes a log aggregation pipeline that indexes raw endpoint telemetry for rapid querying and root-cause analysis.
  • Telemetry Collectors - Gathers detailed process, network, and file activity data via kernel drivers and API hooking for security analysis.
  • Process Lineage Visualizers - Provides a visualizer to map process lineage and parent-child relationships for performing root-cause analysis of attacks.
  • System Call Monitors - Instruments and tracks system calls on Windows to detect suspicious behavior or unauthorized activity.
  • Root Cause Analysis - Parses and indexes endpoint data using a log-aggregation stack to enable breach detection and root-cause analysis.
  • Telemetry Querying - Provides the ability to query collected telemetry and alerts to identify patterns of compromise across the environment.
  • Security Event Monitoring - Includes a graphical interface and dashboards for monitoring logs, metrics, and security events.
  • System Activity Monitoring - Tracks process creation, registry access, and network activity through kernel drivers and API hooking.
  • Network Traffic Monitors - Filters and records network activity to identify communication with malicious domains or unusual data transfers.
  • Docker Container Deployments - Packages the security platform into Docker images to simplify installation and ensure consistent runtime environments.
  • Multi-Container Stacks - Provides a multi-container Docker stack that bundles search, logging, and visualization tools for telemetry analysis.
  • Event Filtering Rules - Processes endpoint telemetry through customizable rule-based filtering to trigger security alerts.
  • Infrastructure Deployment - Enables the deployment of a search, logging, and visualization stack to collect and analyze telemetry from endpoints.
  • Integrity Protection Managers - Uses a dedicated self-protection provider to prevent unauthorized changes to security components and configurations.
  • Agent Self-Protection - Implements a dedicated provider to protect monitoring agents and configurations from unauthorized modifications.
  • Self-Protection Mechanisms - Implements a dedicated self-protection provider to prevent unauthorized modifications to monitoring agents and configurations.
  • Threat Hunting Workflows - Provides workflows for querying indexed security logs and telemetry to proactively identify patterns of compromise.
  • Security Alert Triggers - Defines custom rule sets and policies that trigger security alerts when suspicious activities are detected.
  • Telemetry Filters - Implements customizable rule sets to filter telemetry and security events before they are forwarded to the server.
  • Forensics and Incident Response - Open-source endpoint detection and response platform.

Star history

Star history chart for comodosecurity/openedrStar history chart for comodosecurity/openedr

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does comodosecurity/openedr do?

OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity.

What are the main features of comodosecurity/openedr?

The main features of comodosecurity/openedr are: Endpoint Detection and Response, Intrusion Detection Systems, Telemetry Collection and Aggregation, Event Callbacks, User-Mode API Hooking Frameworks, Process Hierarchy Tracking, Attack Root Cause Analysis, Runtime Threat Detection.

Which projects share features with comodosecurity/openedr?

Projects with overlapping indexed features include: velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… cilium/tetragon — Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments.… aquasecurity/tracee — Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events… influxdata/telegraf — Telegraf is a modular, cross-platform telemetry pipeline designed to collect, process, and route metrics from diverse…

Projects sharing features with Openedr

These projects share indexed features with Openedr. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

Security-Onion-Solutions/securityonion

4,661View on GitHub↗

Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

Shell
View on GitHub↗4,661
  • cilium/tetragoncilium avatar

    cilium/tetragon

    4,753View on GitHub↗

    Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments. It functions as a security policy manager, observability agent, and enforcement engine that hooks into kernel functions and tracepoints to detect privilege escalation, container escapes, and unauthorized system activity. The project distinguishes itself through its ability to perform real-time, in-kernel enforcement, allowing it to synchronously terminate malicious processes or modify function return values before a system call completes. It provides deep Kubernetes integration

    C
    View on GitHub↗4,753
  • Compare all 30 related projects→