Skip to main content
ToolLicensePlatformsPricingAction
Amazon GuardDutyProprietaryAWSCommercialProfile
ATT&CK NavigatorApache-2.0WebOpen SourceProfile
CorelightProprietary (open core)Hardware, WebCommercialProfile
CortexAGPL-3.0-or-laterLinux, WebOpen SourceProfile
CrowdStrike FalconProprietaryWindows, macOS, Linux, WebCommercialProfile
DeTT&CTGPL-3.0-or-laterLinux, macOS, WindowsOpen SourceProfile
Elastic SecurityElastic-2.0 OR SSPL-1.0 OR AGPL-3.0 (open core)Web, Linux, macOS, WindowsFree / CommercialProfile
FleetMIT (core)Linux, macOS, Windows, ChromeOS, iOS, AndroidFree / CommercialProfile
Google SecOpsProprietaryWebCommercialProfile
GraylogSSPL-1.0 (open core)Web, LinuxFree / CommercialProfile
LimaCharlieProprietaryWindows, macOS, Linux, WebFreemiumProfile
Microsoft Defender for EndpointProprietaryWindows, macOS, Linux, iOS, Android, WebCommercialProfile
Microsoft SentinelProprietaryWebCommercialProfile
OpenSearch Security AnalyticsApache-2.0LinuxOpen SourceProfile
osctrlMITLinux, macOS, WindowsOpen SourceProfile
osqueryApache-2.0 OR GPL-2.0-onlyLinux, macOS, WindowsOpen SourceProfile
OSSECGPL-2.0-onlyLinux, macOS, Windows, SolarisOpen SourceProfile
RITAGPL-3.0-onlyLinuxOpen SourceProfile
Security OnionElastic-2.0LinuxFree / CommercialProfile
SentinelOne SingularityProprietaryWindows, macOS, Linux, WebCommercialProfile
ShuffleAGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs)Linux, macOS, WindowsFree / CommercialProfile
SigmaDRL-1.1Platform-agnostic (rule format)FreeProfile
SnortGPL-2.0-onlyLinux, FreeBSDOpen SourceProfile
SplunkProprietaryWeb, Linux, WindowsFreemiumProfile
SysmonProprietaryWindowsFreeProfile
TracecatAGPL-3.0-or-laterLinux, WebFree / CommercialProfile
Uncoder.ioApache-2.0WebFree / CommercialProfile
WazuhGPL-2.0-only with OpenSSL linking exceptionLinux, Windows, macOSFree / CommercialProfile
YARABSD-3-ClauseLinux, macOS, WindowsOpen SourceProfile

Software in SIEM Tools

AWS managed threat detection service that monitors CloudTrail, VPC Flow Logs, and DNS logs for anomalies across accounts and workloads.

LicenseProprietary
PlatformAWS

ATT&CK Navigator

Open Source

MITRE web tool for annotating ATT&CK matrices and visualizing detection and adversary coverage.

LicenseApache-2.0
PlatformWeb

Corelight

Commercial

Commercial Open NDR platform built on Zeek, Suricata, and YARA with sensors and cloud management.

LicenseProprietary (open core)
PlatformHardware, Web

Cortex

Open Source

Open source analysis and response engine that automates observable enrichment and incident actions.

LicenseAGPL-3.0-or-later
PlatformLinux, Web

Cloud-delivered endpoint security platform combining NGAV, EDR, threat intelligence, and managed hunting.

LicenseProprietary
PlatformWindows, macOS, Linux, Web

DeTT&CT

Open Source

Blue team tool that scores log source visibility and detection coverage into ATT&CK Navigator layers.

LicenseGPL-3.0-or-later
PlatformLinux, macOS, Windows

Elastic Security

Free / Commercial

SIEM and XDR built on the Elastic Stack with open detection rules and endpoint integration.

LicenseElastic-2.0 OR SSPL-1.0 OR AGPL-3.0 (open core)
PlatformWeb, Linux, macOS, Windows

Fleet

Free / Commercial

Open device management and osquery fleet platform for querying and managing endpoints.

LicenseMIT (core)
PlatformLinux, macOS, Windows, ChromeOS, iOS, Android

Google SecOps

Commercial

Cloud-native SIEM and SOAR platform, formerly Google Chronicle, with retro-hunting over year-long retention.

LicenseProprietary
PlatformWeb

Graylog

Free / Commercial

Open core log management platform with SIEM features, event definitions, and alerting.

LicenseSSPL-1.0 (open core)
PlatformWeb, Linux

LimaCharlie

Freemium

SecOps cloud platform providing EDR sensor infrastructure, telemetry pipelines, and detection APIs.

LicenseProprietary
PlatformWindows, macOS, Linux, Web

Microsoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.

LicenseProprietary
PlatformWindows, macOS, Linux, iOS, Android, Web

Cloud-native SIEM and SOAR running on Azure with per-GB analytics pricing.

LicenseProprietary
PlatformWeb

Open source SIEM plugin for OpenSearch with native Sigma rule support and free alerting.

LicenseApache-2.0
PlatformLinux

osctrl

Open Source

Go-based fleet manager for osquery endpoints with admin UI, REST API, and distributed query management for scalable telemetry.

LicenseMIT
PlatformLinux, macOS, Windows

osquery

Open Source

Operating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.

LicenseApache-2.0 OR GPL-2.0-only
PlatformLinux, macOS, Windows

OSSEC

Open Source

Open source host-based intrusion detection with log analysis, file integrity monitoring, and active response.

LicenseGPL-2.0-only
PlatformLinux, macOS, Windows, Solaris

RITA

Open Source

Open source framework that analyzes Zeek logs for C2 beaconing, DNS tunneling, and scanning.

LicenseGPL-3.0-only
PlatformLinux

Security Onion

Free / Commercial

Free Linux distribution bundling network monitoring, intrusion detection, and log management.

LicenseElastic-2.0
PlatformLinux

AI-driven endpoint platform with autonomous response, story-line detection, and 1-year data retention.

LicenseProprietary
PlatformWindows, macOS, Linux, Web

Shuffle

Free / Commercial

Open-source SOAR platform that automates security workflows, integrates threat intelligence and case tools, and supports hybrid deployments.

LicenseAGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs)
PlatformLinux, macOS, Windows

Sigma

Free

Generic signature format for describing log detection rules, enabling portable threat detections across different SIEMs.

LicenseDRL-1.1
PlatformPlatform-agnostic (rule format)

Snort

Open Source

Open-source network intrusion detection and prevention engine that inspects traffic with rule-based signatures and protocol analysis.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD

Splunk

Freemium

Search-driven SIEM and observability platform, owned by Cisco since 2024.

LicenseProprietary
PlatformWeb, Linux, Windows

Sysmon

Free

Windows Sysinternals service that logs detailed process, network, and file activity to the event log.

LicenseProprietary
PlatformWindows

Tracecat

Free / Commercial

Open source SOAR platform with workflow automation, cases, and AI-assisted playbook building.

LicenseAGPL-3.0-or-later
PlatformLinux, Web

Uncoder.io

Free / Commercial

Free online translator that converts Sigma and Roota rules into SIEM, EDR, and data lake query languages.

LicenseApache-2.0
PlatformWeb

Wazuh

Free / Commercial

Open-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.

LicenseGPL-2.0-only with OpenSSL linking exception
PlatformLinux, Windows, macOS

YARA

Open Source

Pattern-matching engine that helps malware researchers identify and classify binary samples based on text and binary rules.

LicenseBSD-3-Clause
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is SIEM Tools?

Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.

What topics does the SIEM Tools category cover?

SIEM Log Aggregation & Correlation, Endpoint Detection & Response (EDR), Security Orchestration & Response (SOAR), Network IDS / IPS, Detection Rule Engineering (Sigma / YARA)

About SIEM Tools

Detection engineering tools collect, correlate, and alert on security events from servers, endpoints, and network traffic. The category spans several tool types. SIEM platforms aggregate logs from across an organization and apply correlation rules to surface suspicious activity. EDR agents monitor endpoint processes, file operations, and network connections to detect malware and lateral movement. SOAR platforms automate alert triage and response actions, reducing the time analysts spend on repetitive investigation steps. Network detection engines like Snort and Suricata inspect traffic against signature and protocol anomaly rules, while Zeek provides session-level logging for forensic reconstruction. Detection rule frameworks like Sigma let teams write vendor-neutral rules and convert them to platform-specific query languages. The category also includes YARA, a pattern-matching tool used to identify and classify malware samples by file content. Teams building detection engineering programs use these tools together: SIEM for log aggregation and correlation, EDR for endpoint visibility, SOAR for response automation, and Sigma for portable rule management.

Covered Topics & Disciplines

SIEM Log Aggregation & CorrelationEndpoint Detection & Response (EDR)Security Orchestration & Response (SOAR)Network IDS / IPSDetection Rule Engineering (Sigma / YARA)