- Home
- Security Operations
- Security Information and Event Management
- Matano Open Source Security Data Lake
Matano Open Source Security Data Lake
An open source cloud-native security data lake platform for AWS that normalizes security logs into structured data with Detection-as-Code capabilities and vendor-neutral storage using open standards.

Matano Open Source Security Data Lake
An open source cloud-native security data lake platform for AWS that normalizes security logs into structured data with Detection-as-Code capabilities and vendor-neutral storage using open standards.
Matano Open Source Security Data Lake Description
Matano is an open source cloud-native security data lake platform built specifically for AWS environments. The platform normalizes unstructured security logs into a structured real-time data lake within users' AWS accounts. The tool provides out-of-the-box integration with over 50 security log sources and supports Detection-as-Code functionality using Python for creating custom security detections. It includes automatic import capabilities for Sigma detection rules and features a log transformation pipeline with custom VRL (Vector Remap Language) scripting. Matano uses open table format standards including Apache Iceberg and open schema standards like ECS (Elastic Common Schema) to ensure vendor-neutral data storage. This approach allows users to maintain full ownership of their security data without vendor lock-in. The platform enables direct querying of the security data lake from various Iceberg-compatible analytics engines including AWS Athena, Snowflake, Spark, and Trino. Users can bring their own analytics tools and query engines to analyze the stored security data. Additionally, Matano offers a commercial managed Cloud SIEM solution that builds upon the open source foundation to provide a complete enterprise Security Operations platform.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.