Open-source adversary emulation platform.
Tools that monitor
Detect threats, anomalies or policy violations at runtime.
66 tools indexed
Visualize Windows logon events.
Automated adversary emulation.
Malicious-traffic detection system.
Open-source security data lake on AWS.
Open adversarial exposure validation.
Decentralized, modular honeypot.
Open-source AI agent firewall for MCP and agent egress.
Linux port of Sysinternals Procmon.
Self-hosted open-source WAF.
Open SOC distribution.
Remote SSH for the edge.
Open-source SOAR.
Vendor-agnostic detection rules.
Local-first threat hunting over logs you already have
Open-source adversary emulation framework.
Cross-platform network traffic monitor with threat detection
Open-source IPS, next generation.
Build vulnerable instrumented labs.
High-performance IDS / IPS.
Sigma-based threat hunting and timeline generator for cloud logs.
Battle-tested Sysmon configuration.
Microsoft's Sysmon, on Linux.
All-in-one honeypot platform.