StamusNetworks / Clear-NDR-ISOView external linksLinks
A Suricata based NDR distribution
☆1,590Sep 13, 2025Updated 5 months ago
Alternatives and similar repositories for Clear-NDR-ISO
Users that are interested in Clear-NDR-ISO are comparing it to the libraries listed below
Sorting:
- Scirius is a web application for Suricata ruleset management and threat hunting.☆676Dec 23, 2025Updated last month
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆482Jan 22, 2026Updated 3 weeks ago
- Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OIS…☆6,000Updated this week
- Arkime is an open source, large scale, full packet capturing, indexing, and database system.☆7,300Updated this week
- Docker based Suricata, Elasticsearch, Logstash, Kibana, Scirius aka SELKS☆184Sep 13, 2022Updated 3 years ago
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,107Apr 16, 2021Updated 4 years ago
- Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.☆7,463Feb 7, 2026Updated last week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,334Jan 30, 2026Updated 2 weeks ago
- Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等☆1,266Jul 8, 2023Updated 2 years ago
- MISP (core software) - Open Source Threat Intelligence and Sharing Platform☆6,123Updated this week
- Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own in…☆4,335Feb 7, 2026Updated last week
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,049Oct 19, 2025Updated 3 months ago
- Malicious traffic detection system☆8,236Updated this week
- Automated deployment scripts for the RockNSM network hunting distribution.☆457Jul 2, 2023Updated 2 years ago
- The tool for updating your Suricata rules.☆289Oct 31, 2025Updated 3 months ago
- The Hunting ELK☆3,913Jun 1, 2024Updated last year
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,514Jan 12, 2026Updated last month
- Attack Detection☆1,359Aug 31, 2022Updated 3 years ago
- Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.☆14,722Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,883Jul 25, 2025Updated 6 months ago
- 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝☆8,756Jan 29, 2026Updated 2 weeks ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,475Jan 12, 2026Updated last month
- Main Sigma Rule Repository☆10,109Updated this week
- OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, roo…☆5,025Updated this week
- Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term o…☆2,618Dec 13, 2025Updated 2 months ago
- Open Source Vulnerability Management Platform☆6,255Jan 26, 2026Updated 2 weeks ago
- Suricata IDS/IPS log analytics using the Elastic Stack.☆241Jul 28, 2021Updated 4 years ago
- Automated Adversary Emulation Platform☆6,733Updated this week
- Suricata, Snort and Zeek IDS rule and pcap testing system☆512Jan 9, 2026Updated last month
- Detect Tactics, Techniques & Combat Threats☆2,263Jan 21, 2026Updated 3 weeks ago
- Loki - Simple IOC and YARA Scanner☆3,719Jan 12, 2026Updated last month
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,349Apr 4, 2024Updated last year
- A toolset to make a system look as if it was the victim of an APT attack☆2,710Sep 23, 2025Updated 4 months ago
- Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run yo…☆3,943Jan 27, 2026Updated 2 weeks ago
- Your Everyday Threat Intelligence☆1,949Updated this week
- Open EDR public repository☆2,604Jan 13, 2024Updated 2 years ago
- Configuration files for the SOF-ELK VM☆1,715Jan 21, 2026Updated 3 weeks ago
- Open Cyber Threat Intelligence Platform☆8,212Updated this week
- Investigate suspicious activity by visualizing Sysmon's event log☆431Dec 22, 2023Updated 2 years ago