Loading...
Detection Engineering tools for Open Source: the Detection Engineering options most relevant when Open Source is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 15 cybersecurity tools
Open source Suricata-based NDR system with threat detection and analysis
Searchable repository of Sigma detection rules for threat hunting and SIEM
Open-source detection rules for email attacks like BEC, phishing, and malware
An open source cloud-native security data lake platform for AWS that normalizes security logs into structured data with Detection-as-Code capabilities and vendor-neutral storage using open standards.
A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing, utilizing Message Query Language (MQL) for behavior description.
An open-source platform that builds instrumented environments, simulates attacks, and integrates with Splunk for detection rule development and testing.
A repository of officially managed detection rules for the Falco runtime security monitoring system that identifies threats, abnormal behaviors, and compliance violations through syscall and container event analysis.
A collection of Yara signatures developed by Citizen Lab to detect malware used in targeted attacks against civil society organizations.
GCTI's open-source detection signatures for malware and threat detection
A community-maintained repository of YARA rules for detecting and classifying malware based on patterns and characteristics.
BinaryAlert is an open-source serverless AWS pipeline that automatically scans files uploaded to S3 buckets with YARA rules and generates immediate alerts when malware is detected.
An OCaml Ctypes wrapper for the YARA matching engine that enables malware identification capabilities in OCaml applications.
A community-driven open source project providing interactive notebooks with detection logic, adversary tradecraft, and resources organized according to MITRE ATT&CK framework for threat hunting and detection development.
A Yara ruleset designed to detect PHP shells and other webserver malware for malware analysis and threat detection.
An open source tool that generates YARA rules from installed software on running operating systems for efficient software identification in digital forensic investigations.