awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to corelight/zeek2es

Projects sharing features with Zeek2es

30 open-source projects similar to corelight/zeek2es, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • tenzir/vasttenzir avatar

    tenzir/vast

    742View on GitHub↗

    Tenzir is the data pipeline engine for security teams.

    C++
    View on GitHub↗742
  • security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/securityonion

    4,661View on GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    View on GitHub↗4,661
  • blueteamlabs/sentinel-attackB

    BlueTeamLabs/sentinel-attack

    0View on GitHub↗
    View on GitHub↗0
  • brexhq/substationbrexhq avatar

    brexhq/substation

    402View on GitHub↗

    Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.

    Go
    View on GitHub↗402
  • brimsec/brimB

    brimsec/brim

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • certsocietegenerale/fircertsocietegenerale avatar

    certsocietegenerale/FIR

    2,009View on GitHub↗

    Fast Incident Response

    JavaScript
    View on GitHub↗2,009
  • clong/detectionlabclong avatar

    clong/DetectionLab

    4,904View on GitHub↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    View on GitHub↗4,904
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    View on GitHub↗12,574
  • cyb3rward0g/helkCyb3rWard0g avatar

    Cyb3rWard0g/HELK

    3,926View on GitHub↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    View on GitHub↗3,926
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0View on GitHub↗
    View on GitHub↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0View on GitHub↗
    View on GitHub↗0
  • dogoncouch/logespdogoncouch avatar

    dogoncouch/LogESP

    219View on GitHub↗

    Open Source SIEM (Security Information and Event Management system).

    Python
    View on GitHub↗219
  • endgameinc/eqlE

    endgameinc/eql

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/varnaendgameinc avatar

    endgameinc/varna

    52View on GitHub↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    View on GitHub↗52
  • evilsocket/opensnitchevilsocket avatar

    evilsocket/opensnitch

    12,899View on GitHub↗

    Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in real time. By hooking into kernel-level interfaces, it tracks system-wide network activity and maps connection attempts to specific local processes, allowing users to explicitly permit or deny traffic on a per-application basis. The project distinguishes itself through its ability to manage security policies across multiple distributed nodes from a single, unified dashboard. This centralized management is secured via encrypted socket communication, enabling consistent rule en

    Pythonapplication-firewalldata-breachfirewall
    View on GitHub↗12,899
  • fireeye/capafireeye avatar

    fireeye/capa

    6,062View on GitHub↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    View on GitHub↗6,062
  • foxio-llc/logslashF

    FoxIO-LLC/LogSlash

    0View on GitHub↗
    View on GitHub↗0
  • gamelinux/passivednsgamelinux avatar

    gamelinux/passivedns

    1,737View on GitHub↗

    A network sniffer that logs all DNS server replies for use in a passive DNS setup

    C
    View on GitHub↗1,737
  • intelowlproject/intelowlintelowlproject avatar

    intelowlproject/IntelOwl

    4,605View on GitHub↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    View on GitHub↗4,605
  • jandre/brosqueryJ

    jandre/brosquery

    0View on GitHub↗
    View on GitHub↗0
  • khadinxc/sigma2kqlKhadinxc avatar

    Khadinxc/Sigma2KQL

    3View on GitHub↗

    Sigma Queries turned into KQL for Defender using pysigma - Automated

    Python
    View on GitHub↗3
  • khadinxc/sigma2splKhadinxc avatar

    Khadinxc/Sigma2SPL

    0View on GitHub↗

    Sigma Queries turned into SPL for Splunk Enterprise and Enterprise Security using pysigma - Automated

    Python
    View on GitHub↗0
  • khadinxc/terrasigmaKhadinxc avatar

    Khadinxc/TerraSigma

    3View on GitHub↗

    TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel

    HCL
    View on GitHub↗3
  • lauriewired/ghidramcpLaurieWired avatar

    LaurieWired/GhidraMCP

    7,649View on GitHub↗

    GhidraMCP is a Model Context Protocol server that exposes Ghidra binary analysis and decompilation functions to external intelligence models. It acts as a bridge that connects the Ghidra reverse engineering suite to external tools through a standardized communication protocol, facilitating automated reverse engineering and software auditing. The project enables the extraction of decompiled code and program structural data to populate the context windows of language models. It features a binary symbol management tool capable of dynamic symbol resolution, allowing method and data names to be up

    Java
    View on GitHub↗7,649
  • mariocandela/beelzebubmariocandela avatar

    mariocandela/beelzebub

    1,848View on GitHub↗
    Goacisagentic-ai-securitycloudnative
    View on GitHub↗1,848
  • matanolabs/matanomatanolabs avatar

    matanolabs/matano

    1,676View on GitHub↗

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

    Rust
    View on GitHub↗1,676
  • mitre-attack/attack-navigatormitre-attack avatar

    mitre-attack/attack-navigator

    2,408View on GitHub↗

    Web app that provides basic navigation and annotation of ATT&CK matrices

    TypeScriptcticyber-threat-intelligencecybersecurity
    View on GitHub↗2,408
  • mitre-attack/bzarM

    mitre-attack/bzar

    0View on GitHub↗
    View on GitHub↗0
  • mvelazc0/orianaM

    mvelazc0/Oriana

    0View on GitHub↗
    View on GitHub↗0