awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Cyb3rWard0g avatar

Cyb3rWard0g/HELK

0
View on GitHub↗
3,926 stele·689 fork-uri·Jupyter Notebook·GPL-3.0·7 vizualizări

HELK

HELK este un mediu containerizat de gestionare a informațiilor și evenimentelor de securitate (SIEM) și o platformă de threat hunting. Acesta oferă o implementare axată pe securitate a stack-ului ELK, combinând Elasticsearch, Logstash și Kibana într-o platformă specializată pentru investigarea log-urilor și descoperirea modelelor ascunse în datele de securitate ale rețelei și sistemului.

Proiectul funcționează ca o suită de știință a datelor de securitate, integrând notebook-uri computaționale interactive și instrumente de procesare distribuită pentru a rula machine learning și analize grafice pe log-urile de securitate. Acest lucru permite identificarea modelelor de atac ascunse și a anomaliilor prin maparea relațiilor bazată pe grafuri.

Platforma acoperă o suprafață largă a operațiunilor de securitate, inclusiv implementarea SIEM, agregarea log-urilor și căutarea bazată pe indexare. Utilizează o infrastructură bazată pe containere pentru a implementa setul complet de instrumente pentru analiza log-urilor de securitate și threat hunting.

Features

  • SIEM Deployments - Sets up a centralized system for collecting, indexing, and visualizing security events across an organization.
  • Security Data Science Suites - Integrates interactive notebooks and distributed processing tools for running machine learning on security logs.
  • Security Log Analytics - Runs machine learning and graph analytics on security data using notebooks and distributed processing.
  • Log Indexing Systems - Organizes unstructured security logs into a searchable index for fast retrieval and complex query execution.
  • Security Analysis Platforms - Provides a security-focused deployment of the ELK stack for threat hunting and log analysis.
  • Security Data Science - Utilizes machine learning and graph analytics on security datasets to discover hidden attack patterns and anomalies.
  • Security Relationship Mappings - Maps connections between security entities to identify hidden attack patterns and lateral movement during investigations.
  • Interactive Threat Hunt Notebooks - Integrates interactive computational notebooks for running analytics and validation queries during exploratory threat hunting.
  • Threat Hunting Infrastructures - Deploys a pre-configured security environment via containers to quickly start analyzing network and host data.
  • Containerized SIEM Platforms - Provides a pre-configured set of Docker containers that deploy a full security information and event management stack.
  • Log Analyzers - Hunts for threats and investigates logs using a specialized stack of indexing, visualization, and ingestion tools.
  • Log Analysis - Searches and investigates system logs using the ELK stack to identify threats and suspicious activity.
  • Log Aggregation Pipelines - Collects and transforms raw security events through an ingestion pipeline before indexing them for search.
  • Distributed Data Processing - Spreads heavy machine learning and graph analytic workloads across multiple nodes to handle large security datasets.
  • Container Deployment - Provides a containerized deployment of the entire security toolset to ensure consistent environment setup.
  • Deployment Infrastructure - Provides the underlying containerized technical stack required to host the security analysis environment.
  • Detection Labs - Pre-configured ELK stack for advanced threat hunting analytics.
  • Forensics and Incident Response - Hunting ELK stack with advanced analytic capabilities.
  • Detection and Hunting Tools - An advanced hunting platform based on the Elastic stack.
  • Incident Response Frameworks - Integrated platform for threat hunting and data analysis.
  • Threat Hunting Operations - Stack for threat hunting using elasticsearch and analytics integrations.

Istoric stele

Graficul istoricului de stele pentru cyb3rward0g/helkGraficul istoricului de stele pentru cyb3rward0g/helk

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru HELK

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu HELK.
  • tencent/gtAvatar Tencent

    Tencent/GT

    4,407Vezi pe GitHub↗

    GT is an on-device mobile debugging tool designed to capture network packets, analyze system logs, and profile hardware performance directly on a smartphone. It provides a portable suite of utilities for identifying software bugs and processing bottlenecks without requiring a connection to a host computer. The project features a plugin-based debugging framework that allows for the development of custom functional extensions to implement project-specific debugging logic. It also enables real-time parameter tuning and injection, allowing internal application settings to be modified during execu

    Java
    Vezi pe GitHub↗4,407
  • graylog2/graylog2-serverAvatar Graylog2

    Graylog2/graylog2-server

    8,066Vezi pe GitHub↗

    Graylog2-server is an open-source centralized log management system and aggregator. It functions as a log analysis platform designed to collect, index, and analyze log data from multiple sources within a centralized searchable index. The system provides capabilities for enterprise log aggregation and infrastructure monitoring. It enables the gathering of logs from various servers and applications to facilitate log data analysis and root cause troubleshooting across a network. The platform utilizes a distributed indexing pipeline and message-queue based ingestion to handle log streams. It inc

    Javaamqpgelfgraylog
    Vezi pe GitHub↗8,066
  • awesome-selfhosted/awesome-selfhostedAvatar awesome-selfhosted

    awesome-selfhosted/awesome-selfhosted

    299,516Vezi pe GitHub↗

    This project is a community-curated directory of open-source software designed for deployment in private server environments and home labs. It serves as a comprehensive resource for discovering independent, self-hosted alternatives to mainstream cloud services, enabling users to maintain full data ownership and control over their digital infrastructure. The directory is structured through a hierarchical taxonomy that organizes a vast collection of applications into logical categories, ranging from media management and data analytics to private communication and team productivity tools. It dis

    awesomeawesome-listcloud
    Vezi pe GitHub↗299,516
  • highlight/highlightAvatar highlight

    highlight/highlight

    9,303Vezi pe GitHub↗

    Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed traces to provide a unified view of application health. It functions as a distributed tracing system, an error monitoring service, and a session replay tool. The platform is available as a dockerized monitoring stack for self-hosted deployments on Linux. It distinguishes itself by combining backend observability with a visual recording system that captures document object model changes and network requests to replay user interactions. The system covers several core capability

    TypeScript
    Vezi pe GitHub↗9,303
Vezi toate cele 30 alternative pentru HELK→

Întrebări frecvente

Ce face cyb3rward0g/helk?

HELK este un mediu containerizat de gestionare a informațiilor și evenimentelor de securitate (SIEM) și o platformă de threat hunting. Acesta oferă o implementare axată pe securitate a stack-ului ELK, combinând Elasticsearch, Logstash și Kibana într-o platformă specializată pentru investigarea log-urilor și descoperirea modelelor ascunse în datele de securitate ale rețelei și sistemului.

Care sunt principalele funcționalități ale cyb3rward0g/helk?

Principalele funcționalități ale cyb3rward0g/helk sunt: SIEM Deployments, Security Data Science Suites, Security Log Analytics, Log Indexing Systems, Security Analysis Platforms, Security Data Science, Security Relationship Mappings, Interactive Threat Hunt Notebooks.

Care sunt câteva alternative open-source pentru cyb3rward0g/helk?

Alternativele open-source pentru cyb3rward0g/helk includ: graylog2/graylog2-server — Graylog2-server is an open-source centralized log management system and aggregator. It functions as a log analysis… tencent/gt — GT is an on-device mobile debugging tool designed to capture network packets, analyze system logs, and profile… awesome-selfhosted/awesome-selfhosted — This project is a community-curated directory of open-source software designed for deployment in private server… highlight/highlight — Highlight is a full-stack observability platform and monitoring system that aggregates logs, errors, and distributed… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… comodosecurity/openedr — OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to…