Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
☆4,863Sep 3, 2026Updated this week
Alternatives and similar repositories for securityonion
Users that are interested in securityonion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.☆16,759Updated this week
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,137Apr 16, 2021Updated 5 years ago
- Main Sigma Rule Repository☆10,977Updated this week
- Digging Deeper....☆4,230Updated this week
- Open Cyber Threat Intelligence Platform☆9,889Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.☆7,932Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,949Jul 25, 2025Updated last year
- MISP (core software) - Open Source Threat Intelligence and Sharing Platform☆6,499Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,481Updated this week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,504Aug 25, 2026Updated last week
- Automated Adversary Emulation Platform☆7,238Aug 27, 2026Updated last week
- Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OIS…☆6,603Updated this week
- A Suricata based NDR distribution☆1,593Sep 13, 2025Updated 11 months ago
- IntelOwl: manage your Threat Intelligence at scale☆4,696Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝☆9,455Updated this week
- The Hunting ELK☆3,930Jun 1, 2024Updated 2 years ago
- A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering env…☆8,992Jun 23, 2026Updated 2 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,334Updated this week
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,509Jan 12, 2026Updated 7 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,652Jan 12, 2026Updated 7 months ago
- Six Degrees of Domain Admin☆10,610Mar 2, 2026Updated 6 months ago
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,718Jan 5, 2026Updated 7 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆30,994Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Detect Tactics, Techniques & Combat Threats☆2,338Aug 6, 2026Updated 3 weeks ago
- A repository of sysmon configuration modules☆3,124Updated this week
- Automate the creation of a lab environment complete with security tooling and logging best practices☆5,014Jul 6, 2024Updated 2 years ago
- ☆2,429Oct 14, 2023Updated 2 years ago
- Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.☆2,424Updated this week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,654Aug 25, 2026Updated last week
- A curated list of awesome YARA rules, tools, and people.☆4,269Jun 15, 2026Updated 2 months ago
- Arkime is an open source, large scale, full packet capturing, indexing, and database system.☆7,462Updated this week
- ☆64Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Sysmon configuration file template with default high-quality event tracing☆5,636Jul 3, 2024Updated 2 years ago
- The FLARE team's open-source tool to identify capabilities in executable files.☆6,163Updated this week
- Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mand…☆7,795Oct 16, 2025Updated 10 months ago
- Cortex: a Powerful Observable Analysis and Active Response Engine☆1,619Jun 30, 2026Updated 2 months ago
- ☆55Updated this week
- A curated list of tools for incident response☆9,372Jul 15, 2026Updated last month
- This repository contains the scanner component for Greenbone Community Edition.☆4,809Updated this week