A curated knowledge base to build, run and mature a SOC (including CSIRT).
-
Updated
Sep 25, 2026
A curated knowledge base to build, run and mature a SOC (including CSIRT).
A Suricata based NDR distribution
Threat-hunting tool for Linux
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
Transform Linux Audit logs for SIEM usage
Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
monitor macOS for malicious activity
Open-source framework to detect outliers in Elasticsearch events
LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications, and deletions for administrators and security researchers.
A security monitoring solution for Kubernetes
Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)
Free, self-hosted M365 configuration drift monitoring. Baseline your tenant, detect changes at the property level, and restore in one click. For MSSPs and admins.
Defensomania is a security monitoring and incident response card game.
WinLogAgent - A user-friendly, modern, and readily deployable Windows log collection client that makes it easy to forward collected logs to a SOC or SIEM.
Extract TLS certificates from pcap files or network interfaces, fingerprint TLS client/server interactions with ja3/ja3s
Passive intrusion detection for Laravel. Logs SQL injection, XSS, RCE, scanners and recon probes against 150+ patterns, with full app context. Dashboard, fail2ban/blocklist export, Slack alerts, REST API. It never blocks - you decide what to do with the data. IDS, not WAF.
A Passive DNS backend and collector
Wazuh detection engineering, SIEM integrations, and SOC automation lab.
Finds the detection rules in your SIEM that are running blind
This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup a Suricata Port Mirrored Server
To associate your repository with the security-monitoring topic, visit your repo's landing page and select "manage topics."