Best Security Monitoring & Threat Hunting tools by public signals

These picks are computed from scored public evidence. Use the openness column in the ranking to separate OSI-approved, source-available, open-core, proprietary, and unverified-license tools.

Use Case Rankings

Ordered by ToolVitals score, health, shipping, confidence, and then adoption as a tie-breaker.

# Tool Health Shipping Openness Stars Score Status
01 Lyrie AI
Autonomous AI cybersecurity agent.
90 89 OSI-approved OSS 375 92 Active
02 InnerWarden
Autonomous EDR for Linux with kernel-level eBPF detection and AI triage.
85 95 OSI-approved OSS 164 92 Active
03 osctrl
Fast and efficient osquery management.
76 84 OSI-approved OSS 509 83 Active
04 Wildbox
Open-source security platform with SIEM, SOAR, WAF, and more in a self-hosted package.
76 80 OSI-approved OSS 130 82 Active
05 SEKOIA.IO
SEKOIA.IO Documentation - The Intelligence-Driven SaaS SIEM
77 72 License unknown 56 81 Active
06 Wardex
Private-cloud XDR and SIEM platform for detection engineering and SOC workflows.
80 69 OSI-approved OSS 1 80 Active
07 Security Onion
Open platform for threat hunting, security monitoring, and log management.
78 36 License unknown 4.8k 70 Warning
08 Catalyst
Self-hosted incident response platform and ticket system.
62 14 OSI-approved OSS 536 54 Warning
09 Gridwolf
Open-source unified security operations & threat intelligence platform for OT/ICS environments with ontology-driven dashboards
49 24 OSI-approved OSS 45 52 Critical
10 Shrike
Any log in. Normalized OCSF out. Open-source security data platform.
37 10 OSI-approved OSS 0 41 Critical
11 WatchYourLAN
Lightweight network IP scanner written in Go. With notifications, history, export to Grafana
39 0 OSI-approved OSS 7.1k 36 Critical
12 Matano
Cloud-native security lake platform for threat hunting.
27 0 OSI-approved OSS 1.7k 33 Critical