How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
Tenzir is the data pipeline engine for security teams.
The main features of tenzir/vast are: Security Data Analytics, Security Logging and SIEM, Detection and Hunting Tools, Network Security Monitoring.
Open-source alternatives to tenzir/vast include: security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It… matanolabs/matano — Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale… corelight/zeek2es — A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON… zeek/zeek — Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level… ntop/ndpi — nDPI is a deep packet inspection toolkit and network protocol classifier designed to identify protocols and detect… skeeto/endlessh — Endlessh is an SSH tarpit and network honeypot designed to mitigate automated SSH brute force attacks. It acts as a…