Category: Network Defense

Cilium

cilium: eBPF-based Networking, Security, and Observability

cilium: eBPF-based Networking, Security, and Observability Cilium is open source software for providing and transparently securing network connectivity and load-balancing between application workloads such as application containers or processes. Cilium operates at Layer 3/4...

pmacct

pmacct: passive network monitoring tools

pmacct pmacct is a small set of multi-purpose passive network monitoring tools. It can account, classify, aggregate, replicate and export forwarding-plane data, ie. IPv4 and IPv6 traffic; collect and correlate control-plane data via BGP...

cloud-native monitoring system

nightingale: enterprise-level cloud-native monitoring system

Nightingale Nightingale is an enterprise-level cloud-native monitoring system, which can be used as a drop-in replacement for Prometheus for alerting and management. Nightingale is a cloud-native monitoring system by All-In-On design, that supports enterprise-class...

Kubernetes policy engine

Polaris: open source policy engine for Kubernetes

Polaris Securing workloads in Kubernetes is an important part of overall cluster security. The overall goal should be to ensure that containers are running with as minimal privileges as possible. This includes avoiding privilege...

Hardening Windows Tool

AHWT: Hardening tool for Windows operating systems

AHWT – another hardening tool for Windows operating systems The program is a script generator with a collection of parameters and recommendations from CIS Benchmarks and DoD STIGs with some adjustments. All parameters are...

Real Intelligence Threat Analytics

RITA: Real Intelligence Threat Analytics

Real Intelligence Threat Analytics Real Intelligence Threat Analytics (RITA) is an open-source framework for network traffic analysis. The framework ingests Bro Logs, and currently supports the following analysis features: Beaconing Detection: Search for signs of...

Snort 3

Snort: Intrusion Prevention System

Snort++ Snort 3 is the next generation Snort IPS (Intrusion Prevention System).   This version of Snort++ includes new features as well as all Snort 2.X features and bug fixes for the base version...

endpoint security

wazuh: Host and endpoint security

Wazuh Wazuh helps you gain deeper security visibility into your infrastructure by monitoring hosts at an operating system and application level. This solution, based on lightweight multi-platform agents, provides the following capabilities:   Log...

cloud-native security tool

Falco: A cloud-native security tool

Falco Falco is a cloud-native security tool. It provides near real-time threat detection for cloud, container, and Kubernetes workloads by leveraging runtime insights. Falco can monitor events defined via customizable rules from various sources, including the...