How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Open Source SIEM (Security Information and Event Management system).
Sigma Queries turned into SPL for Splunk Enterprise and Enterprise Security using pysigma - Automated
The main features of khadinxc/sigma2spl are: Security Logging and SIEM.
Projects with overlapping indexed features include: security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… corelight/zeek2es — A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON… dogoncouch/logesp — Open Source SIEM (Security Information and Event Management system). evilsocket/opensnitch — Opensnitch is a host-based application firewall for Linux that monitors and intercepts outbound network connections in… gamelinux/passivedns — A network sniffer that logs all DNS server replies for use in a passive DNS setup. certsocietegenerale/fir — Fast Incident Response.