Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
☆4,805Aug 14, 2026Updated this week
Alternatives and similar repositories for securityonion
Users that are interested in securityonion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.☆16,524Updated this week
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,136Apr 16, 2021Updated 5 years ago
- Main Sigma Rule Repository☆10,886Updated this week
- Digging Deeper....☆4,176Updated this week
- Open Cyber Threat Intelligence Platform☆9,807Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.☆7,874Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,946Jul 25, 2025Updated last year
- MISP (core software) - Open Source Threat Intelligence and Sharing Platform☆6,469Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,406Updated this week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,483Updated this week
- Automated Adversary Emulation Platform☆7,189Updated this week
- Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OIS…☆6,545Updated this week
- A Suricata based NDR distribution☆1,589Sep 13, 2025Updated 11 months ago
- IntelOwl: manage your Threat Intelligence at scale☆4,667Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝☆9,417Aug 4, 2026Updated last week
- The Hunting ELK☆3,929Jun 1, 2024Updated 2 years ago
- A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering env…☆8,934Jun 23, 2026Updated last month
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,307Aug 3, 2026Updated last week
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,510Jan 12, 2026Updated 7 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,635Jan 12, 2026Updated 7 months ago
- Six Degrees of Domain Admin☆10,604Mar 2, 2026Updated 5 months ago
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,701Jan 5, 2026Updated 7 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆30,506Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Detect Tactics, Techniques & Combat Threats☆2,326Aug 6, 2026Updated last week
- A repository of sysmon configuration modules☆3,112Updated this week
- Automate the creation of a lab environment complete with security tooling and logging best practices☆5,009Jul 6, 2024Updated 2 years ago
- ☆2,427Oct 14, 2023Updated 2 years ago
- Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.☆2,411Updated this week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,629Aug 4, 2026Updated last week
- A curated list of awesome YARA rules, tools, and people.☆4,255Jun 15, 2026Updated last month
- Arkime is an open source, large scale, full packet capturing, indexing, and database system.☆7,444Updated this week
- ☆63Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Sysmon configuration file template with default high-quality event tracing☆5,621Jul 3, 2024Updated 2 years ago
- The FLARE team's open-source tool to identify capabilities in executable files.☆6,134Updated this week
- Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mand…☆7,780Oct 16, 2025Updated 9 months ago
- Cortex: a Powerful Observable Analysis and Active Response Engine☆1,613Jun 30, 2026Updated last month
- ☆54Updated this week
- A curated list of tools for incident response☆9,323Jul 15, 2026Updated last month
- This repository contains the scanner component for Greenbone Community Edition.☆4,769Updated this week