Showing 16 of 16 projects
Open-source interface for querying, analyzing, visualizing, and managing Elasticsearch data.
An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.
An open-source, participative security engine that detects and blocks malicious IPs using crowdsourced threat intelligence.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A flexible framework for alerting on anomalies, spikes, or patterns in Elasticsearch data.
A simple framework for alerting on anomalies, spikes, or other patterns in Elasticsearch data.
A diagnostic logging library for .NET applications with first-class support for structured event data.
Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.
An open-source threat hunting platform with advanced analytics capabilities built on ELK stack, Apache Spark, and Jupyter notebooks.
A desktop app that reconstructs Claude Code's full execution trace from local session logs, showing every tool call, subagent, and token.
A large collection of real-world system log datasets for AI-driven log analytics research.
A collection of 200 Windows EVTX event log samples mapped to MITRE ATT&CK techniques for detection testing and threat hunting.
A lightweight, single-binary tool for viewing and filtering terminal logs in a real-time web interface.
A Python-based engine for automatic creation of super timelines from computer system logs and files for digital forensic analysis.
A collection of ready-to-use KQL queries for threat hunting, detection, and analytics in Microsoft Defender for Endpoint and Azure Sentinel.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.