Threat Detection Tools
Threat detection is the practice of identifying suspicious activity, vulnerabilities, and signs of compromise across computers, networks, and applications. It helps security teams find potential attacks early, investigate unusual behavior, and reduce the time between an intrusion and a response. Detection can use system and network logs, known indicators, behavioral analysis, or low-level operating system events. Some approaches focus on continuous monitoring, while others analyze collected data to uncover patterns that may otherwise go unnoticed.
Open source tools in this area include host monitors, log analysis systems, network sensors, honeypots, and rule-based or behavior-based detection engines. When choosing one, consider the systems it supports, data sources and integrations, deployment requirements, alert quality, maintenance activity, and license. These tools can be useful to security teams, system administrators, researchers, and organizations building their own monitoring workflows.
3 repositories · updated August 14, 2026

ADR: Uber's Enterprise Security System for AI Agents
ADR (Agentic AI Detection and Response) is an enterprise security system developed by Uber to secure AI agents. It offers critical capabilities like observability, security benchmarking, and threat detection, ensuring the safe operation of both employee and customer-facing AI applications. This open-source project is deployed in production at Uber and was accepted to MLSys 2026.

Tailpipe: An Open Source SIEM for Instant Log Insights with DuckDB
Tailpipe is an open source SIEM designed for instant log insights, powered by DuckDB. It allows users to analyze millions of events in seconds directly from their terminal using SQL queries. This tool is ideal for developers and security professionals seeking a lightweight, efficient, and flexible solution for log analysis across various cloud and application sources.

theProtector: Real-time Linux Security Monitoring with eBPF and Honeypots
theProtector is a powerful Linux Bash script designed for real-time host-based security monitoring. It leverages advanced techniques like eBPF kernel monitoring, YARA pattern matching, and network honeypots to detect and respond to threats. This tool provides multi-layer security for paranoid admins on a budget, ensuring continuous protection with minimal overhead.