Tools
SIEM & Threat Detection tools 17 tools
17 tools
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Splunk Security Content
Malicious traffic detection system
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.
A framework for secure and scalable network traffic analysis - https://netcap.io
Web-based dashboard for Fail2Ban log filtering and blocklist control
Main Sigma Rule Repository
The pattern matching swiss knife
IntelOwl: manage your Threat Intelligence at scale
Bloodhound Reporting for Blue and Purple Teams
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Web-based Traffic and Security Network Traffic Monitoring
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).