A security framework for detecting threats, fraud, and abuse through event ingestion and risk scoring.

Tirreno is an open-source, self-hosted web app and server that provides a security framework for threat detection, fraud prevention, and abuse monitoring. It focuses on detecting threats within application logic and compromised accounts that often bypass traditional firewalls, SIEMs, and WAFs. By monitoring activity inside the product, it identifies breaches that occur through account takeovers and logic abuse.
The software is deployed as a web application on a server and integrates with other products via SDKs and API calls. It allows administrators to ingest events with full context to monitor security incidents through a real-time dashboard. The system is designed for a straightforward installation process and can be deployed via Docker, Composer, or manual ZIP extraction on Unix-like systems.
Tirreno is built as a low-dependency PHP and PostgreSQL application, requiring PHP 8.0 to 8.3 and PostgreSQL 12 or greater. It is designed for a wide range of environments, including SaaS platforms, e-commerce marketplaces, and mission-critical applications, including those in air-gapped deployments. The architecture supports the detection of payment fraud, fake reviews, and promotional code exploitation in online stores, as well as the prevention of cross-tenant data leakage and privilege escalation in digital platforms. It also extends to industrial control systems to protect operational technology from unauthorized access.
This tool serves as an internal security layer for organizations needing detailed audit trails and fraud detection within their own infrastructure.
A network-wide DNS sinkhole that blocks unwanted content for all devices on a local network.
Automate security workflows and playbooks using a low code builder with integrated AI agents and case management.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.