How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in real time. By hooking into kernel-level interfaces, it tracks system-wide network activity and maps connection attempts to specific local processes, allowing users to explicitly permit or deny traffic on a per-application basis. The project distinguishes itself through its ability to manage security policies across multiple distributed nodes from a single, unified dashboard. This centralized management is secured via encrypted socket communication, enabling consistent rule en
Open Source SIEM (Security Information and Event Management system).
The main features of dogoncouch/logesp are: Security Logging and SIEM.
Projects with overlapping indexed features include: security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… corelight/zeek2es — A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON… evilsocket/opensnitch — Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in… gamelinux/passivedns — A network sniffer that logs all DNS server replies for use in a passive DNS setup. khadinxc/sigma2kql — Sigma Queries turned into KQL for Defender using pysigma - Automated. certsocietegenerale/fir — Fast Incident Response.