A Suricata based NDR distribution
☆1,588Sep 13, 2025Updated 5 months ago
Alternatives and similar repositories for Clear-NDR-ISO
Users that are interested in Clear-NDR-ISO are comparing it to the libraries listed below
Sorting:
- Scirius is a web application for Suricata ruleset management and threat hunting.☆675Dec 23, 2025Updated 2 months ago
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆484Feb 19, 2026Updated 2 weeks ago
- Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OIS…☆6,022Updated this week
- Arkime is an open source, large scale, full packet capturing, indexing, and database system.☆7,310Updated this week
- Docker based Suricata, Elasticsearch, Logstash, Kibana, Scirius aka SELKS☆184Sep 13, 2022Updated 3 years ago
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,105Apr 16, 2021Updated 4 years ago
- Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.☆7,504Updated this week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,344Feb 19, 2026Updated 2 weeks ago
- Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等☆1,261Jul 8, 2023Updated 2 years ago
- MISP (core software) - Open Source Threat Intelligence and Sharing Platform☆6,150Feb 27, 2026Updated last week
- Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own in…☆4,434Feb 27, 2026Updated last week
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,136Oct 19, 2025Updated 4 months ago
- Malicious traffic detection system☆8,264Updated this week
- Automated deployment scripts for the RockNSM network hunting distribution.☆456Jul 2, 2023Updated 2 years ago
- The tool for updating your Suricata rules.☆293Oct 31, 2025Updated 4 months ago
- The Hunting ELK☆3,912Jun 1, 2024Updated last year
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,515Jan 12, 2026Updated last month
- Attack Detection☆1,358Aug 31, 2022Updated 3 years ago
- Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.☆14,881Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,891Jul 25, 2025Updated 7 months ago
- 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝☆8,819Jan 29, 2026Updated last month
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,492Jan 12, 2026Updated last month
- Main Sigma Rule Repository☆10,156Updated this week
- OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, roo…☆5,022Feb 9, 2026Updated 3 weeks ago
- Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term o…☆2,623Dec 13, 2025Updated 2 months ago
- Open Source Vulnerability Management Platform☆6,284Feb 13, 2026Updated 3 weeks ago
- Suricata IDS/IPS log analytics using the Elastic Stack.☆240Jul 28, 2021Updated 4 years ago
- Automated Adversary Emulation Platform☆6,781Feb 28, 2026Updated last week
- Suricata, Snort and Zeek IDS rule and pcap testing system☆511Feb 27, 2026Updated last week
- Detect Tactics, Techniques & Combat Threats☆2,264Jan 21, 2026Updated last month
- Your Everyday Threat Intelligence☆1,954Feb 12, 2026Updated 3 weeks ago
- Loki - Simple IOC and YARA Scanner☆3,729Jan 12, 2026Updated last month
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,353Apr 4, 2024Updated last year
- A toolset to make a system look as if it was the victim of an APT attack☆2,714Sep 23, 2025Updated 5 months ago
- Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run yo…☆3,958Feb 20, 2026Updated 2 weeks ago
- Open EDR public repository☆2,608Jan 13, 2024Updated 2 years ago
- Configuration files for the SOF-ELK VM☆1,720Jan 21, 2026Updated last month
- Investigate suspicious activity by visualizing Sysmon's event log☆431Dec 22, 2023Updated 2 years ago
- Open Cyber Threat Intelligence Platform☆8,960Updated this week