StreamAlert

StreamAlert

Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.

Visit Website

StreamAlert: A Serverless Real-Time Data Analysis Framework

StreamAlert is a serverless, real-time data analysis framework that enables users to ingest, analyze, and receive alerts on data from any environment.

Utilization in Computer Security

It is utilized by computer security teams to analyze terabytes of log data on a daily basis for incident detection and response. Rules are crafted using Python, and logs along with alerts can be searched retroactively. Additionally, deployment is automated and designed with security in mind.

It supports dozens of log types and more

It supports a wide variety of log types, includes a set of community rules, and is completely open source and customizable.