Open-Source Network Management, Monitoring, ITOM, and Security Analytics
-
Updated
Sep 25, 2026 - Elixir
Open-Source Network Management, Monitoring, ITOM, and Security Analytics
Normalize, lint, and validate OCSF security data to ensure event mapping quality and identify data loss across your pipelines.
Security analytics data lake for GRC & Trust: governance datasets, findings pipelines, compliance analytics, audit trails, and control-plane reporting.
Portable SecOps content, structure and metrics above open standards (CACAO v2, Sigma, OSCAL, D3FEND, OCSF), compiled to n8n, Temporal or LangGraph. A Digital Commons for sovereign security operations in the EU.
Open security data platform in Rust: Sigma detection on OCSF events at 129k events/s per core, verified against SigmaHQ's recorded attacks. SIEM, SOAR and incident response in one system. Pre-alpha.
Observo — independent third-party profile of a public API surface, by API Evangelist. Observo AI built an AI-native data pipeline (telemetry pipeline) platform that optimizes security and observability data in flight, filtering, enriching, and normalizing logs, metrics, and traces into standard schemas like OCSF to cut SIEM and observability data v
Multi-client console chat app built with Java and the OCSF framework
Plugin-based, multi-format log analysis platform for network and infrastructure device logs. Declarative YAML parsers with a ReDoS-safe grok engine, OCSF + OpenTelemetry normalisation, ClickHouse storage, raw archive with replay, and an agentic layer for proactive investigation and root cause analysis. Built on .NET 10.
Verifiable identity and tamper-evident OCSF audit records for AI agents — signed event chains, offline verification, agent mandates.
Extracts and structures Fortigate Log Reference documentation into machine-readable CSV schemas, and translates them into ECS and OCSF field mappings. Built for security engineers and data teams building parsers, normalization pipelines, or field references.
Ingests Cisco ASA, FortiGate, Suricata, and Linux logs → normalizes to OCSF-Slim v1.8 → stores in SQLite → serves via REST API + SSE for live SIEM integration. Air-gap ready, single static binary, no cloud dependencies. Built for SIH 2026 (#25165).
Field guide to building detection platforms that hold under real-world conditions. SIEM-agnostic: OCSF and Sigma throughout.
One light open-source security agent (eBPF/ETW) feeding a canonical, fix-first Findings Engine. OCSF-native, no per-seat license — you own your data.
Information-flow control runtime for LLM agents: label data, track flows through tool calls, and block prompt-injection exfiltration at the sink. Python + TypeScript, CaMeL-style strict mode, OPA, OCSF/SARIF, AgentDojo-benchmarked.
131 deterministic cloud & AI security skills — OCSF 1.8, MCP tools, HITL-gated remediation. AWS · GCP · Azure · K8s · SaaS.
Mixed security logs in. Queryable OCSF on Apache Iceberg out. Raw evidence, quarantine, Kafka streaming, and Trino SQL.
EKSIR — analyst-grade AI SOC workbench: deterministic triage + agent-persona LLM investigation with a human sign-off gate. Self-hostable, multi-tenant.
To associate your repository with the ocsf topic, visit your repo's landing page and select "manage topics."