Home/Free Security Operations Tools

Free Security Operations Tools

Run an effective security operations centre with free and open source tools. Browse SIEM platforms, SOAR automation, log management, and threat detection tools for SOC teams.

411 tools·44 sub-categories·Updated April 2026

Showing 24 of 411 tools

grafana icon

grafana

grafana/grafana

Tool

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

68.4K
10 months ago
PowerShell icon

PowerShell

PowerShell/PowerShell

Framework

PowerShell for every system!

47.6K
10 months ago
awx icon

awx

ansible/awx

Tool

AWX provides a web-based user interface, REST API, and task engine built on top of Ansible. It is one of the upstream projects for Red Hat Ansible Automation Platform.

14.6K
10 months ago
wazuh icon

wazuh

wazuh/wazuh

Tool

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

14.5K
3 months ago
awesome-security icon

awesome-security

sbilly/awesome-security

Documentation

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

13.8K
3 months ago
crowdsec icon

crowdsec

crowdsecurity/crowdsec

Tool

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

12.2K
3 months ago
quickemu icon

quickemu

quickemu-project/quickemu

Tool

Quickly create and run optimised Windows, macOS and Linux virtual machines

12.0K
10 months ago
test-your-sysadmin-skills icon

test-your-sysadmin-skills

trimstray/test-your-sysadmin-skills

Educational Resource

A collection of Linux Sysadmin Test Questions and Answers. Test your knowledge and skills in different fields with these Q/A.

11.1K
8 months ago
pyroscope icon

pyroscope

grafana/pyroscope

Tool

Continuous Profiling Platform. Debug performance issues down to a single line of code

10.6K
10 months ago
90DaysOfCyberSecurity icon

90DaysOfCyberSecurity

farhanashrafdev/90DaysOfCyberSecurity

Educational Resource

This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, covering topics such as Network+, Security+, Linux, Python, Traffic Analysis, Git, ELK, AWS, Azure, and Hacking. The repository also includes a `LEARN.md

10.2K
8 months ago
sigma icon

sigma

SigmaHQ/sigma

Dataset

Main Sigma Rule Repository

10.0K
3 months ago
devops-resources icon

devops-resources

bregman-arie/devops-resources

Documentation

DevOps resources - Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP

9.1K
8 months ago
pipeline icon

pipeline

tektoncd/pipeline

Framework

A cloud-native Pipeline resource.

8.7K
10 months ago
falco icon

falco

falcosecurity/falco

Tool

Cloud Native Runtime Security

8.6K
3 months ago
anteon icon

anteon

getanteon/anteon

Tool

Anteon (formerly Ddosify) - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI, Self-Hosted, and Cloud

8.5K
10 months ago
school-of-sre icon

school-of-sre

linkedin/school-of-sre

Educational Resource

At LinkedIn, we are using this curriculum for onboarding our entry-level talents into the SRE role.

8.0K
8 months ago
graylog2-server icon

graylog2-server

Graylog2/graylog2-server

Tool

Free and open log management

7.9K
3 months ago
beehive icon

beehive

muesli/beehive

Tool

A flexible event/agent & automation system with lots of bees 🐝

6.4K
10 months ago
lefthook icon

lefthook

evilmartians/lefthook

Tool

Fast and powerful Git hooks manager for any type of projects.

6.0K
10 months ago
rundeck icon

rundeck

rundeck/rundeck

Tool

Enable Self-Service Operations: Give specific users access to your existing tools, services, and scripts

5.8K
10 months ago
flagsmith icon

flagsmith

Flagsmith/flagsmith

Tool

Flagsmith is an open source feature flagging and remote config service. Self-host or use our hosted version at https://app.flagsmith.com.

5.7K
10 months ago
cortex icon

cortex

cortexproject/cortex

Tool

A horizontally scalable, highly available, multi-tenant, long term Prometheus.

5.6K
10 months ago
Azure-Sentinel icon

Azure-Sentinel

Azure/Azure-Sentinel

Tool

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

5.4K
3 months ago
nifi icon

nifi

apache/nifi

Framework

Apache NiFi

5.4K
10 months ago

Can't find the right tool?

Describe what you need in plain English and our AI will find the best match from 10,000+ security tools.

Frequently Asked Questions

What is a SIEM and do I need one?

A SIEM (Security Information and Event Management) system collects, correlates, and analyzes log data from across your environment to detect threats in real time. Any organization with more than a handful of systems benefits from a SIEM. Free options include Wazuh, Elastic SIEM, and Graylog.

What is the best free SIEM platform?

Wazuh is the most widely deployed free SIEM, combining log analysis, file integrity monitoring, vulnerability detection, and compliance reporting. Elastic SIEM (part of the Elastic Stack) is powerful for large-scale deployments. Graylog offers excellent log management with security analytics.

What is SOAR?

SOAR (Security Orchestration, Automation, and Response) platforms automate repetitive SOC tasks — alert triage, threat enrichment, and incident response workflows. Free SOAR tools include TheHive with Cortex, Shuffle, and n8n configured for security workflows.

How do I build a SOC on a budget?

A cost-effective SOC stack typically includes: Wazuh (SIEM/EDR), Suricata (network IDS), TheHive (case management), MISP (threat intelligence), and Shuffle (SOAR). This open source stack provides enterprise-grade capabilities at near-zero licensing cost.