Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Intrusion Detection

Intrusion Detection

125 projects

Showing 36 of 125 projects

How-to-Secure-A-Linux-Server
How-to-Secure-A-Linux-Server

A comprehensive, evolving guide to hardening a Linux server with practical steps and security best practices.

#linux-server#server-hardening#self-hosted-security
Stars29.6k
Forks2.0k
Last commit10 days ago
osquery
osqueryC++

A SQL-powered framework for instrumenting, monitoring, and analyzing operating systems across Linux, macOS, and Windows.

#fleet-management#hacktoberfest#thrift-api
Stars23.4k
Forks2.6k
Last commit8 days ago
osquery
osqueryC++

A SQL-powered framework for instrumenting, monitoring, and analyzing operating systems across Linux, macOS, and Windows.

#fleet-management#hacktoberfest#thrift-api
Stars23.4k
Forks2.6k
Last commit8 days ago
fail2ban
fail2banPython

A daemon that scans log files and bans IP addresses with too many failed authentication attempts using firewall rules.

#ip-banning#system-daemon#gplv2
Stars18.2k
Forks1.5k
Last commit1 month ago
wazuh
wazuhC++

An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.

#container-security#siem#malware-detection
Stars16.3k
Forks2.4k
Last commit6 hours ago
CrowdSec
CrowdSecGo

An open-source, participative security engine that detects and blocks malicious IPs using crowdsourced threat intelligence.

#crowdsourced-security#waf#ids
Stars14.3k
Forks683
Last commit11 hours ago
Honeypots
HoneypotsPython

A curated list of awesome honeypot resources, tools, and related components for cybersecurity research and defense.

#honeypot#awesome-list#malware-analysis
Stars10.5k
Forks1.4k
Last commit1 month ago
Maltrail
MaltrailPython

A malicious traffic detection system that monitors network traffic for blacklisted threats and suspicious activities using public feeds and heuristics.

#sensor#blacklist-feeds#security
Stars8.6k
Forks1.3k
Last commit14 hours ago
Endlessh
EndlesshC

An SSH tarpit that slowly sends an endless banner to trap and waste attackers' time.

#honeypot#server-hardening#c-program
Stars8.5k
Forks300
Last commit2 years ago
WatchYourLAN
WatchYourLANGo

A lightweight network IP scanner with a web GUI that monitors hosts, sends notifications, and exports data to Grafana.

#network-scanner#selfhosted#ip-scanner
Stars7.1k
Forks249
Last commit10 months ago
MISP
MISPPHP

An open-source platform for collecting, storing, sharing, and acting upon cybersecurity threat intelligence and indicators.

#threat-sharing#security#fraud-management
Stars6.4k
Forks1.6k
Last commit1 day ago
OSSEC
OSSECC

Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.

#real-time-alerting#siem#policy-monitoring
Stars5.0k
Forks1.1k
Last commit25 days ago
PCAPTools
PCAPTools

A curated list of open-source and research tools for capturing, analyzing, and processing network packet captures (PCAP files).

#traffic-analysis#pcap#research-tools
Stars3.4k
Forks480
Last commit10 months ago
Security Onion
Security Onion

A Linux distribution for threat hunting, enterprise security monitoring, and log management.

#enterprise-security#siem#ids
Stars3.1k
Forks526
Last commit5 years ago
OpenRASP
OpenRASPC++

Open source Runtime Application Self-Protection (RASP) solution that integrates security directly into application servers via instrumentation.

#php-security#waf#web-security
Stars3.0k
Forks621
Last commit9 months ago
OpenCanary
OpenCanaryPython

A modular, low-resource network honeypot that mimics services to detect breaches and alert on attacker interactions.

#honeypot#python#intrusion-detection
Stars2.9k
Forks405
Last commit1 day ago
MHN
MHNPython

A centralized management and data collection server for deploying and monitoring multiple honeypot sensors.

#hacktoberfest#honeypot-management#flask-application
Stars2.5k
Forks623
Last commit1 year ago
CanaryTokens
CanaryTokensPython

Deploy honeytokens across your network to detect unauthorized access and data exfiltration attempts.

#honeytoken#smtp#security
Stars2.1k
Forks291
Last commit13 hours ago
JA4+
JA4+Rust

A suite of network fingerprinting standards for TLS, TCP, HTTP, SSH, and other protocols to facilitate threat detection and security analysis.

#ja3-fingerprint#traffic-analysis#ja4-fingerprint
Stars2.0k
Forks180
Last commit2 days ago
stenographer
stenographerGo

A high-performance packet capture solution that buffers all network traffic to disk for fast retrieval of specific subsets.

#bpf#disk-buffering#high-performance
Stars1.8k
Forks233
Last commit5 years ago
sshesame
sshesameGo

A lightweight SSH honeypot that logs all connection attempts and activity without executing commands.

#honeypot#ssh-honeypot#deceptive-server
Stars1.7k
Forks108
Last commit1 year ago
Kippo
KippoPython

A medium interaction SSH honeypot that logs brute force attacks and attacker shell interactions.

#attack-logging#ssh-honeypot#python
Stars1.7k
Forks280
Last commit2 years ago
SELKS
SELKSShell

A Linux distribution for network detection and response (NDR) built around Suricata, providing a complete NDR platform.

#iso-builder#suricata#ids
Stars1.6k
Forks290
Last commit10 months ago
Acra
AcraGo

Database security suite providing field-level encryption, SQL injection prevention, and intrusion detection for sensitive data.

#crypto#encryption-server#sensitive-data
Stars1.5k
Forks140
Last commit3 months ago
Network Flight Simulator (flightsim)
Network Flight Simulator (flightsim)Go

A lightweight utility to generate malicious network traffic patterns for evaluating security controls and network visibility.

#c2-traffic#malware-simulation#command-line-tool
Stars1.4k
Forks145
Last commit2 years ago
Honeytrap
HoneytrapGo

An extensible open-source framework for running, monitoring, and managing honeypots to detect and analyze cyber threats.

#honeypot#splunk#kafka
Stars1.3k
Forks180
Last commit2 years ago
Artillery
ArtilleryPython

An open-source blue team tool that protects Linux and Windows systems via honeypots, monitoring, and alerting.

#honeypot#windows-security#alerting-system
Stars1.0k
Forks204
Last commit4 years ago
honeypots
honeypotsPython

A Python package with 30 low-high level honeypots for monitoring network traffic, bots, and credential attacks.

#pypi#honeypot#protocol-emulation
Stars982
Forks140
Last commit7 months ago
DECAF (Dynamic Executable Code Analysis Framework)
DECAF (Dynamic Executable Code Analysis Framework)C

A dynamic binary analysis framework based on QEMU for whole-system taint analysis and security research.

#taint-analysis#malware-analysis#intrusion-detection
Stars836
Forks167
Last commit1 year ago
Dionaea
DionaeaPython

A low-interaction honeypot that emulates vulnerable services to capture malware and analyze attacks.

#honeypot#protocol-emulation#security
Stars808
Forks199
Last commit2 years ago
MIDAS: Detecting Microcluster Anomalies in Edge Streams
MIDAS: Detecting Microcluster Anomalies in Edge StreamsC++

A real-time anomaly detection algorithm for dynamic graph streams, identifying intrusions, fraud, and fake ratings with constant memory and update time.

#aaai2020#c-plus-plus#denial-of-service
Stars776
Forks98
Last commit2 years ago
Laika BOSS
Laika BOSSPython

A scalable, modular object scanner and intrusion detection system that extracts, flags, and enriches files with metadata.

#file-analysis#metadata-extraction#python
Stars751
Forks161
Last commit1 year ago
ssh-honeypot
ssh-honeypotC

A low-interaction SSH honeypot that logs attacker IPs, usernames, and passwords for security intelligence.

#ssh-honeypot#intrusion-detection#hassh-fingerprinting
Stars677
Forks250
Last commit1 year ago
HASSH
HASSHPython

A network fingerprinting standard that identifies SSH client and server implementations via MD5 hashes of algorithm sets.

#network-forensics#iot-security#ssh-fingerprinting
Stars553
Forks76
Last commit1 year ago
dcept
dceptPython

A honeytoken-based tripwire for detecting Active Directory credential theft and privilege escalation attempts.

#honeytoken#forensic-timeline#windows-security
Stars504
Forks102
Last commit4 years ago
Evebox
EveboxRust

A web-based GUI for viewing and managing Suricata EVE security events stored in Elasticsearch or SQLite.

#netsec#suricata#ids
Stars498
Forks78
Last commit17 hours ago
Page 1 of 4Next

Related Tags

#Network Security88#Honeypot45#Security Monitoring38#Security33#Suricata33#Cybersecurity32#Threat Detection29#Python19#Go18#Ids17#Docker17#Ssh Honeypot15
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub