Open Source Security Automation (SIEM/SOAR) Software

Security Automation (SIEM/SOAR) software centralizes the collection of event logs and network traffic to identify threats. These tools automate responses to security incidents through predefined playbooks and risk scoring. This type of software serves security analysts and network administrators who need to manage threat intelligence and case files on their own hardware. By self-hosting these apps, you keep sensitive login attempts and network activity logs off external servers. This approach ensures that security workflows and decoy service data remain within a private infrastructure.

This page lists 5 open source tools in the Security Automation (SIEM/SOAR) category. The most popular are Pi-hole, Tracecat and IPBan. Most use the AGPL-3.0 or eupl-1.2 license, and 4 offer an official Docker image.

Open Source Software.io

Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.