SIEM Tools
Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Amazon GuardDuty | Proprietary | AWS | Commercial | Profile→ |
| ATT&CK Navigator | Apache-2.0 | Web | Open Source | Profile→ |
| Corelight | Proprietary (open core) | Hardware, Web | Commercial | Profile→ |
| Cortex | AGPL-3.0-or-later | Linux, Web | Open Source | Profile→ |
| CrowdStrike Falcon | Proprietary | Windows, macOS, Linux, Web | Commercial | Profile→ |
| DeTT&CT | GPL-3.0-or-later | Linux, macOS, Windows | Open Source | Profile→ |
| Elastic Security | Elastic-2.0 OR SSPL-1.0 OR AGPL-3.0 (open core) | Web, Linux, macOS, Windows | Free / Commercial | Profile→ |
| Fleet | MIT (core) | Linux, macOS, Windows, ChromeOS, iOS, Android | Free / Commercial | Profile→ |
| Google SecOps | Proprietary | Web | Commercial | Profile→ |
| Graylog | SSPL-1.0 (open core) | Web, Linux | Free / Commercial | Profile→ |
| LimaCharlie | Proprietary | Windows, macOS, Linux, Web | Freemium | Profile→ |
| Microsoft Defender for Endpoint | Proprietary | Windows, macOS, Linux, iOS, Android, Web | Commercial | Profile→ |
| Microsoft Sentinel | Proprietary | Web | Commercial | Profile→ |
| OpenSearch Security Analytics | Apache-2.0 | Linux | Open Source | Profile→ |
| osctrl | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| osquery | Apache-2.0 OR GPL-2.0-only | Linux, macOS, Windows | Open Source | Profile→ |
| OSSEC | GPL-2.0-only | Linux, macOS, Windows, Solaris | Open Source | Profile→ |
| RITA | GPL-3.0-only | Linux | Open Source | Profile→ |
| Security Onion | Elastic-2.0 | Linux | Free / Commercial | Profile→ |
| SentinelOne Singularity | Proprietary | Windows, macOS, Linux, Web | Commercial | Profile→ |
| Shuffle | AGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs) | Linux, macOS, Windows | Free / Commercial | Profile→ |
| Sigma | DRL-1.1 | Platform-agnostic (rule format) | Free | Profile→ |
| Snort | GPL-2.0-only | Linux, FreeBSD | Open Source | Profile→ |
| Splunk | Proprietary | Web, Linux, Windows | Freemium | Profile→ |
| Sysmon | Proprietary | Windows | Free | Profile→ |
| Tracecat | AGPL-3.0-or-later | Linux, Web | Free / Commercial | Profile→ |
| Uncoder.io | Apache-2.0 | Web | Free / Commercial | Profile→ |
| Wazuh | GPL-2.0-only with OpenSSL linking exception | Linux, Windows, macOS | Free / Commercial | Profile→ |
| YARA | BSD-3-Clause | Linux, macOS, Windows | Open Source | Profile→ |
Software in SIEM Tools
Amazon GuardDuty
CommercialAWS managed threat detection service that monitors CloudTrail, VPC Flow Logs, and DNS logs for anomalies across accounts and workloads.
ATT&CK Navigator
Open SourceMITRE web tool for annotating ATT&CK matrices and visualizing detection and adversary coverage.
Corelight
CommercialCommercial Open NDR platform built on Zeek, Suricata, and YARA with sensors and cloud management.
Cortex
Open SourceOpen source analysis and response engine that automates observable enrichment and incident actions.
CrowdStrike Falcon
CommercialCloud-delivered endpoint security platform combining NGAV, EDR, threat intelligence, and managed hunting.
DeTT&CT
Open SourceBlue team tool that scores log source visibility and detection coverage into ATT&CK Navigator layers.
Elastic Security
Free / CommercialSIEM and XDR built on the Elastic Stack with open detection rules and endpoint integration.
Fleet
Free / CommercialOpen device management and osquery fleet platform for querying and managing endpoints.
Google SecOps
CommercialCloud-native SIEM and SOAR platform, formerly Google Chronicle, with retro-hunting over year-long retention.
Graylog
Free / CommercialOpen core log management platform with SIEM features, event definitions, and alerting.
LimaCharlie
FreemiumSecOps cloud platform providing EDR sensor infrastructure, telemetry pipelines, and detection APIs.
Microsoft Defender for Endpoint
CommercialMicrosoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.
Microsoft Sentinel
CommercialCloud-native SIEM and SOAR running on Azure with per-GB analytics pricing.
OpenSearch Security Analytics
Open SourceOpen source SIEM plugin for OpenSearch with native Sigma rule support and free alerting.
osctrl
Open SourceGo-based fleet manager for osquery endpoints with admin UI, REST API, and distributed query management for scalable telemetry.
osquery
Open SourceOperating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.
OSSEC
Open SourceOpen source host-based intrusion detection with log analysis, file integrity monitoring, and active response.
RITA
Open SourceOpen source framework that analyzes Zeek logs for C2 beaconing, DNS tunneling, and scanning.
Security Onion
Free / CommercialFree Linux distribution bundling network monitoring, intrusion detection, and log management.
SentinelOne Singularity
CommercialAI-driven endpoint platform with autonomous response, story-line detection, and 1-year data retention.
Shuffle
Free / CommercialOpen-source SOAR platform that automates security workflows, integrates threat intelligence and case tools, and supports hybrid deployments.
Sigma
FreeGeneric signature format for describing log detection rules, enabling portable threat detections across different SIEMs.
Snort
Open SourceOpen-source network intrusion detection and prevention engine that inspects traffic with rule-based signatures and protocol analysis.
Splunk
FreemiumSearch-driven SIEM and observability platform, owned by Cisco since 2024.
Sysmon
FreeWindows Sysinternals service that logs detailed process, network, and file activity to the event log.
Tracecat
Free / CommercialOpen source SOAR platform with workflow automation, cases, and AI-assisted playbook building.
Uncoder.io
Free / CommercialFree online translator that converts Sigma and Roota rules into SIEM, EDR, and data lake query languages.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
YARA
Open SourcePattern-matching engine that helps malware researchers identify and classify binary samples based on text and binary rules.
Frequently Asked Questions
What is SIEM Tools?→
Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.
What topics does the SIEM Tools category cover?→
SIEM Log Aggregation & Correlation, Endpoint Detection & Response (EDR), Security Orchestration & Response (SOAR), Network IDS / IPS, Detection Rule Engineering (Sigma / YARA)
About SIEM Tools
Detection engineering tools collect, correlate, and alert on security events from servers, endpoints, and network traffic. The category spans several tool types. SIEM platforms aggregate logs from across an organization and apply correlation rules to surface suspicious activity. EDR agents monitor endpoint processes, file operations, and network connections to detect malware and lateral movement. SOAR platforms automate alert triage and response actions, reducing the time analysts spend on repetitive investigation steps. Network detection engines like Snort and Suricata inspect traffic against signature and protocol anomaly rules, while Zeek provides session-level logging for forensic reconstruction. Detection rule frameworks like Sigma let teams write vendor-neutral rules and convert them to platform-specific query languages. The category also includes YARA, a pattern-matching tool used to identify and classify malware samples by file content. Teams building detection engineering programs use these tools together: SIEM for log aggregation and correlation, EDR for endpoint visibility, SOAR for response automation, and Sigma for portable rule management.
Covered Topics & Disciplines
Related Security Categories
Disk and memory forensics, malware sandboxes, and incident response collection platforms.
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.