Best SIEM & Threat Detection Tools

Explore leading tools in the SIEM & Threat Detection category, including open-source options and SaaS products. Compare features, use cases, and find the best fit for your workflow.

5 open-source projects · 5 SaaS products

Top open-source SIEM & Threat Detection

These projects are active, self-hostable choices for knowledge management teams evaluating alternatives to SaaS tools.

Wazuh logo

Wazuh

Unified security platform for detection, response, and compliance

Stars
14,110
License
Unknown
Last commit
3 days ago
CActive
Sigma logo

Sigma

Standardized, vendor-agnostic signatures for log-based threat detection

Stars
9,856
License
Unknown
Last commit
3 days ago
PythonActive
OSSEC logo

OSSEC

Unified host-based intrusion detection, log analysis, and response platform

Stars
4,946
License
Unknown
Last commit
10 months ago
CStable
RedELK logo

RedELK

Centralized SIEM for Red Teams to monitor and detect Blue Team activity

Stars
2,600
License
BSD-3-Clause
Last commit
22 days ago
PythonActive
Matano logo

Matano

Serverless security data lake for AWS with detection-as-code

Stars
1,630
License
Apache-2.0
Last commit
11 months ago
RustStable
Most starred project
14,110★

Unified security platform for detection, response, and compliance

Recently updated
3 days ago

Wazuh delivers real‑time intrusion detection, log analysis, vulnerability scanning, and compliance reporting across on‑prem, cloud, and container environments with native Elastic Stack integration and automated response actions.

Dominant language
C • 2 projects

Expect a strong C presence among maintained projects.

Popular SaaS Platforms to Replace

Understand the commercial incumbents teams migrate from and how many open-source alternatives exist for each product.

Elastic Security SIEM logo

Elastic Security SIEM

Modern, cost-efficient SIEM with years of searchable data.

SIEM & Threat Detection
Alternatives tracked
5 alternatives
Exabeam logo

Exabeam

SIEM and UEBA for threat detection and response

SIEM & Threat Detection
Alternatives tracked
5 alternatives
IBM QRadar SIEM logo

IBM QRadar SIEM

Enterprise SIEM for real-time threat detection and compliance.

SIEM & Threat Detection
Alternatives tracked
5 alternatives
Microsoft Sentinel logo

Microsoft Sentinel

Cloud-native SIEM and SOAR solution for intelligent security analytics and threat detection across enterprise environments

SIEM & Threat Detection
Alternatives tracked
5 alternatives
Sumo Logic Cloud SIEM logo

Sumo Logic Cloud SIEM

Cloud-native SIEM with real-time analytics and AI-guided investigation.

SIEM & Threat Detection
Alternatives tracked
5 alternatives
Most compared product
5 open-source alternatives

Elastic SIEM centralizes security data, enables hunting and detections aligned to MITRE ATT&CK, and links with the Elastic platform for investigation.

Leading hosted platforms

Frequently replaced when teams want private deployments and lower TCO.

Explore related categories

Browse neighbouring categories in Security to widen your evaluation.