Skip to main content
buildradar
Sign in
Topic · siem

siem

Tracked open-source repos tagged siem, sorted by stars.

Repos
28
Total stars
67,022
Avg. stars
2,394
Share
0.00%

Topics that frequently appear alongside siem on the same repo.

Recent risers

Repos created in the last 90 days, tagged siem.

No new repos tagged with this topic in the last 90 days.

  • wazuh@wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

    16,753+37Star change over the last 7 days
  • sigma@SigmaHQ

    Main Sigma Rule Repository

    10,973+16Star change over the last 7 days
  • graylog2-server@Graylog2

    Free and open log management

    8,121+1Star change over the last 7 days
  • Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

    3,128+18Star change over the last 7 days
  • RedELK@outflanknl

    Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

    2,669+3Star change over the last 7 days
  • AiSOC@beenuar

    Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

    2,363-22Star change over the last 7 days
  • VictoriaLogs@VictoriaMetrics

    Fast and easy to use database for logs, which can efficiently handle terabytes of logs

    2,216+16Star change over the last 7 days
  • elastdocker@sherifabdlnaby

    🐳 Elastic Stack (ELK) v9+ on Docker with Compose. Pre-configured out of the box to enable Logging, Metrics, APM, Alerting, ML, and SIEM features. Up with a Single Command.

    2,068+0Star change over the last 7 days
  • awesome-lists@mthcht

    Awesome Security lists for SOC/CERT/CTI

    1,896+2Star change over the last 7 days
  • A curated knowledge base to build, run and mature a SOC (including CSIRT).

    1,809+0Star change over the last 7 days
  • matano@matanolabs

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

    1,694+0Star change over the last 7 days
  • pfelk@pfelk

    pfSense/OPNsense + Elastic Stack

    1,224+1Star change over the last 7 days
  • agentic-soc-platform@FunnyWolf

    Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform (AI SOC)

    1,167+5Star change over the last 7 days
  • Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

    1,109+3Star change over the last 7 days
  • sentinel-attack@edoardogerosa

    Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

    1,077+0Star change over the last 7 days
  • A collective list of public APIs for use in security. Contributions welcome

    990+2Star change over the last 7 days
  • laurel@threathunters-io

    Transform Linux Audit logs for SIEM usage

    856+0Star change over the last 7 days
  • tenzir@tenzir

    Tenzir is the data pipeline engine for security teams.

    758+1Star change over the last 7 days
  • SIEM@TonyPhipps

    SIEM Tactics, Techiques, and Procedures

    730+0Star change over the last 7 days
  • pql@runreveal

    Pipelined Query Language

    707-2Star change over the last 7 days
  • ThreatHunting-Keywords@mthcht

    Awesome list of keywords and artifacts for Threat Hunting sessions

    673+0Star change over the last 7 days
  • PurpleCloud@iknowjason

    A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4

    657+2Star change over the last 7 days
  • Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

    641+0Star change over the last 7 days
  • UTMStack@utmstack

    Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

    581+1Star change over the last 7 days
  • tailpipe@turbot

    select * from logs; Tailpipe is an open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, right from your terminal.

    580+0Star change over the last 7 days
  • CyberBlue@cyberblu3s

    CyberSecurity BLUE TEAM containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and Network Analysis

    547+0Star change over the last 7 days
  • mcp-security@google
    522+2Star change over the last 7 days
  • OpenUBA@GACWR

    A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [BETA]

    517+4Star change over the last 7 days
← Back to topics