Skip to content

Open-Source Blue Team & Threat Detection

by @releaseport · 10 tools

Detect, correlate, and respond to intrusions — host-based SIEMs, network IDS, DFIR endpoint agents, log analyzers, deception traps, and community detection rules.

wazuh open source

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Added 2mo
crowdsec open source

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

1 tracking Added 2mo
Velociraptor open source

Digging Deeper....

Added 2mo
Canary Tokens open source

Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.

Added 2mo
Sigma open source

Main Sigma Rule Repository

Added 2mo
fail2ban open source

Daemon to ban hosts that cause multiple authentication errors

Added 2mo
Zeek open source

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Added 2mo
Maltrail open source

Malicious traffic detection system

Added 2mo
Hayabusa open source

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Added 2mo
Intel Owl open source

IntelOwl: manage your Threat Intelligence at scale

Added 2mo

Beta — feedback welcome: [email protected]