Showing 36 of 50 projects
Open-source interface for querying, analyzing, visualizing, and managing Elasticsearch data.
An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.
An open-source, participative security engine that detects and blocks malicious IPs using crowdsourced threat intelligence.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A generic and open signature format for describing log event detections, shareable across SIEM systems.
A simple framework for alerting on anomalies, spikes, or other patterns in Elasticsearch data.
A flexible framework for alerting on anomalies, spikes, or patterns in Elasticsearch data.
A diagnostic logging library for .NET applications with first-class support for structured event data.
Open Source Host-based Intrusion Detection System performing log analysis, file integrity checking, rootkit detection, and active response.
An open-source threat hunting platform with advanced analytics capabilities built on ELK stack, Apache Spark, and Jupyter notebooks.
A desktop app that reconstructs Claude Code's full execution trace from local session logs, showing every tool call, subagent, and token.
A large collection of real-world system log datasets for AI-driven log analytics research.
A collection of 200 Windows EVTX event log samples mapped to MITRE ATT&CK techniques for detection testing and threat hunting.
A lightweight, single-binary tool for viewing and filtering terminal logs in a real-time web interface.
A Python-based engine for automatic creation of super timelines from computer system logs and files for digital forensic analysis.
A collection of ready-to-use KQL queries for threat hunting, detection, and analytics in Microsoft Defender for Endpoint and Azure Sentinel.
A terminal user interface for viewing and filtering logs from journald, auditd, file systems, Docker, Podman, and Kubernetes with highlighting.
A Windows application for collecting, viewing, and filtering logs from various sources like OutputDebugString, files, sockets, and ADB.
A command-line forensics tool for tracking USB device connection history on GNU/Linux systems.
A full-screen ASCII performance monitor for Linux that logs system and process activity with detailed resource utilization.
A standalone Python tool for applying SIGMA detection rules to EVTX, Auditd, Sysmon for Linux, and other log formats.
A high-performance desktop application for viewing and analyzing large log files and network traces, with support for automotive formats like DLT.
Interactive grep tool for real-time filtering of streaming data with archived mode for static files.
A cross-platform universal log viewer built with .NET for reading, parsing, and analyzing various log formats.
An open-source framework for detecting command and control communication through network traffic analysis using Zeek logs.
A small command-line tool to view and filter JSON log files with customizable formatting and Lua-based filtering.
A web-based GUI for viewing and managing Suricata EVE security events stored in Elasticsearch or SQLite.
A collection of built-in detection rules and policies for Panther, a modern SIEM, enabling security monitoring as code.
A specialized Amazon Kinesis stream reader that delivers CloudWatch Logs data to other systems like Elasticsearch and S3 in near real-time.
A community-driven collection of pre-built security analytics queries and rules for auditing and threat detection in Google Cloud.
A fast terminal-based tool for realtime text scanning, regex extraction, and visualization of logs and structured data.
A collection of Splunk SPL queries and prototypes for threat hunting and detection engineering.
A TUI pager for exploring and analyzing tabular data from logs, CSV, JSON, and streams with vi-like keybindings.
A Rust tool for drawing low-resolution graphs directly in the terminal for quick data analysis from logs and text files.
An interactive terminal-based viewer for exploring and analyzing structured JSON logs.
An advanced Apache logfile security analyzer for post-attack forensics, detecting web application attacks using multiple detection techniques.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.