Security Automation (SIEM/SOAR) software centralizes the collection of event logs and network traffic to identify threats. These tools automate responses to security incidents through predefined playbooks and risk scoring. This type of software serves security analysts and network administrators who need to manage threat intelligence and case files on their own hardware. By self-hosting these apps, you keep sensitive login attempts and network activity logs off external servers. This approach ensures that security workflows and decoy service data remain within a private infrastructure.
This page lists 5 open source tools in the Security Automation (SIEM/SOAR) category. The most popular are Pi-hole, Tracecat and IPBan. Most use the AGPL-3.0 or eupl-1.2 license, and 4 offer an official Docker image.
A network-wide DNS sinkhole that blocks unwanted content for all devices on a local network.
Automate security workflows and playbooks using a low code builder with integrated AI agents and case management.
Blocks malicious IP addresses by detecting failed login attempts from event viewers and log files.
A deception runtime framework that deploys adaptive LLM-powered decoy services to collect threat intelligence.
A security framework for detecting threats, fraud, and abuse through event ingestion and risk scoring.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.