Skip to content
OpenCatalogcurated by FLOSSK

Browse & filter

Filter by platform, license text, maturity, maintenance cadence, and editorial tags like privacy-focused or self-hosted. Search matches names, summaries, tags, and use cases.

13 tools match your filters

High-performance IDS/IPS and network security monitoring with multi-threading, TLS inspection options, and Lua scripting.

idsipsnetworksocdetection

Classic packet-sniffing IDS/IPS with rule language and community rule feeds; Snort 3 improves scaling.

idsipsnetworksoc

Network security monitor producing rich logs (conn, DNS, HTTP, SSL, files) for analytics—not a classic IDS signature engine.

nsmnetworksocthreat-huntinglogs

Threat intelligence sharing platform: IOCs, galaxies, taxonomies, sync between communities, and API automation.

threat-inteliocsharingsocself-hosted

Open cyber threat intelligence platform with knowledge graph, connectors (MISP, STIX/TAXII), and investigation UI.

threat-intelstixgraphsocself-hosted

Security incident response platform: cases, tasks, observables, MISP sync, and timeline collaboration.

incident-responsecase-managementsocself-hosted
Honorable mention

Observable analysis engine powering TheHive: run analyzers and responders against IOCs via a unified API.

socenrichmentautomationiocself-hosted

Open-source security automation (SOAR) with visual workflows, webhooks, and app integrations for SOC glue code.

soarautomationsocworkflowsself-hosted

Endpoint visibility and DFIR: Velociraptor Query Language (VQL), hunts, notebooks, and artifact packs across fleets.

dfiredrhuntingendpointsoc

Linux distribution and platform bundling Zeek, Suricata, Elastic stack, and analyst UIs for NSM and log hunting.

socnsmsiemdistrotraining

Large-scale full packet capture, indexing, and search (SPIE) with a web UI—successor to the Moloch lineage for NSM teams.

nsmpcapsocthreat-huntingnetwork

Collaborative incident response platform: cases, timelines, evidence, tasks, and integrations with MISP, VT, and webhooks.

dfirincident-responsecase-managementsoc

Analyze files, IPs, domains, and URLs in one request by fanning out to many free/TI analyzers (YARA, PE, DNS, etc.).

threat-intelligenceenrichmentmalwareapisoc