Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
☆4,769Jul 24, 2026Updated this week
Alternatives and similar repositories for securityonion
Users that are interested in securityonion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.☆16,284Updated this week
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,131Apr 16, 2021Updated 5 years ago
- Main Sigma Rule Repository☆10,796Updated this week
- Digging Deeper....☆4,120Updated this week
- Open Cyber Threat Intelligence Platform☆9,722Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.☆7,816Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,939Jul 25, 2025Updated last year
- MISP (core software) - Open Source Threat Intelligence and Sharing Platform☆6,433Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,261Updated this week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,459Updated this week
- Automated Adversary Emulation Platform☆7,135Updated this week
- Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OIS…☆6,490Updated this week
- A Suricata based NDR distribution☆1,589Sep 13, 2025Updated 10 months ago
- IntelOwl: manage your Threat Intelligence at scale☆4,635Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝☆9,361Jun 23, 2026Updated last month
- The Hunting ELK☆3,929Jun 1, 2024Updated 2 years ago
- A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering env…☆8,881Jun 23, 2026Updated last month
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,269Updated this week
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,511Jan 12, 2026Updated 6 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,610Jan 12, 2026Updated 6 months ago
- Six Degrees of Domain Admin☆10,580Mar 2, 2026Updated 4 months ago
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,688Jan 5, 2026Updated 6 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆29,993Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Detect Tactics, Techniques & Combat Threats☆2,311Jun 2, 2026Updated last month
- A repository of sysmon configuration modules☆3,091Jul 13, 2026Updated last week
- Automate the creation of a lab environment complete with security tooling and logging best practices☆5,007Jul 6, 2024Updated 2 years ago
- ☆2,421Oct 14, 2023Updated 2 years ago
- Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.☆2,358Updated this week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,610Updated this week
- A curated list of awesome YARA rules, tools, and people.