A Linux distribution for network detection and response (NDR) built around Suricata, providing a complete NDR platform.
Clear NDR Community (formerly SELKS) is a Linux distribution specifically designed for network detection and response (NDR). It provides a complete, pre-configured platform built around the Suricata intrusion detection system to monitor network traffic, identify threats, and facilitate security response. The project solves the complexity of deploying and integrating multiple NDR tools by offering a ready-to-use ISO image.
Security engineers, network administrators, and SOC teams who need an open-source, self-hosted NDR solution for monitoring network security and detecting intrusions.
Developers choose Clear NDR Community because it packages enterprise-grade NDR capabilities into an easy-to-deploy ISO, eliminating integration hassles. Its Suricata foundation and dedicated tooling provide a robust, cost-effective alternative to commercial NDR platforms.
A Suricata based NDR distribution
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Packages Suricata and essential tools into a single ISO, eliminating manual integration hassles as described in the README's focus on a 'complete platform'.
Bootable ISO images simplify installation, with build scripts provided for custom creation on Debian systems, making deployment straightforward.
Offers a no-desktop variant via build scripts, ideal for appliance or server deployments without GUI overhead.
Centers on Suricata for robust IDS/IPS capabilities, providing enterprise-grade threat detection in an open-source package.
Building ISOs requires a specific Debian version and sudo access, as noted in the README, which can hinder customization or use in non-Debian environments.
Heavy reliance on stamusctl for management, with configuration files in a separate repo, may tie users to Stamus Networks' ecosystem and complicate independence.
Documentation and issue tracking are hosted externally, as mentioned in the README, potentially slowing down troubleshooting and community support.