tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.
-
Updated
Apr 7, 2026 - PHP
tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.
Cloud Security Operations Orchestrator
vPrioritizer enables us to understand the contextualized risk (vPRisk) on asset-vulnerability relationship level across the organization, for teams to make more informed decision about what (vulnerability/ties) they should remediate (or can afford not to) and on which (asset/s)
Security Analytics Engine - Anomaly Detection in Web Traffic
Detection of network traffic anomalies using unsupervised machine learning
Digital Twin Driven Security Analytics for the Industrial Internet of Things.
Plug into extended SecOps: Bring Google Cloud's analytics to your local network. tshark captures on-prem, GCP transforms to UDM. Scalable, event-driven, via Terraform.
This repository contains an end-to-end walkthrough to leverage Google Cloud services to demonstrate Solution Accelerators for few business domains
Production-ready authentication framework that saves you weeks of development. Features enterprise-grade security: 2FA/TOTP, LDAP integration, intelligent rate limiting, session fingerprinting, brute-force protection, security analytics dashboard, comprehensive audit logging, and granular role-based access control.
Power Query collection for SentinelOne - KQL queries, data transformations, and analysis templates for security operations and threat hunting
An end-to-end AI system for detecting insider threats using a hybrid machine learning approach (Isolation Forest + XGBoost). Features a high-performance ETL pipeline using DuckDB, real-time inference via FastAPI, and integrated Explainable AI (SHAP) for transparent risk assessment on the CERT R4.2 dataset.
AI-powered cybersecurity monitoring platform that detects suspicious digital attacks, analyzes threat patterns, visualizes intrusion risks, and assists in proactive cyber defense management.
LIZARD (visuaLized Indicators for Zonal Anomaly Risk Detection) - Interactive fraud pattern visualization and ML-based anomaly detection platform.
This project demonstrates SSH authentication log analysis using Splunk SIEM to detect malicious activity such as brute-force attacks, unauthorized access attempts, and suspicious SSH behavior. It simulates real-world SOC analyst workflows, including log ingestion, SPL queries, dashboards, and alerting.
🛡️ CyberSentinel – Threat Intel + Log Correlation Dashboard. An analyst-grade security tool that ingests threat intelligence, parses SSH/Apache logs, correlates IOCs, and generates real-time alerts.
Patent-aligned cybersecurity prototype implementing dynamic trust-based adaptive access control using credential integrity, competence evidence, behavioral risk, and event-driven trust recomputation.
Cybersecurity Intrusion Detection System using LightGBM
Standalone edge protection sensor and fleet management platform
End-to-end network security pipeline for phishing data detection with data validation, ETL processing, and MongoDB storage using Python.
A scalable, Lakehouse-based SIEM architecture using Apache Kafka, Spark, Hadoop, and Hive for real-time security threat detection and large-scale log analytics
Add a description, image, and links to the security-analytics topic page so that developers can more easily learn about it.
To associate your repository with the security-analytics topic, visit your repo's landing page and select "manage topics."