Best Self-hosted Threat Detection, SIEM & Incident Response tools in 2026

13 self-hosted open source alternatives in this category

13 services found

Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

32.1k
2.5k
Last commit: 25d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.8k
1.3k
Last commit: 3mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

17k
1.5k
Last commit: 13d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.6k
576
Last commit: 1d ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Graylog

Graylog

Centralized log management and analysis platform

8k
1.1k
Last commit: 8h ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.5k
323
Last commit: 12h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19
NetAlertX

NetAlertX

Network device scanner and presence detection with alerts

5.8k
370
Last commit: 2d ago

Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.

Alternative to:
Fing
Fing
+8
Canarytokens

Canarytokens

Honeytokens that alert when accessed or executed

2.8k
396
Last commit: 14d ago

Canarytokens generates honeytokens (URLs, files, credentials, docs) that alert you when an attacker touches them, helping detect breaches early.

Alternative to:
Thinkst Canary
Thinkst Canary
+2
Beelzebub

Beelzebub

Low-code honeypot framework using LLMs for safe system deception

1.9k
176
Last commit: 1d ago

Secure low-code honeypot framework that uses LLMs to simulate high-interaction systems across SSH/HTTP/TCP and MCP, with metrics and cloud-native deployment options.

Alternative to:
Thinkst Canary
Thinkst Canary
+1
GlobaLeaks

GlobaLeaks

Secure whistleblowing and anonymous reporting platform

1.4k
323
Last commit: 1d ago

Open-source platform for secure, anonymous whistleblowing and case handling, designed for privacy by default and adaptable to many reporting use cases.

tirreno

tirreno

Security analytics framework for in-app threat detection and risk

1.1k
114
Last commit: 13d ago

Open-source security analytics framework for event tracking, in-app threat detection, and risk management to protect applications from abuse, bots, and account takeover.

Alternative to:
Splunk
Splunk
+4
Fail2Ban-Report

Fail2Ban-Report

Web dashboard for Fail2Ban logs and centralized UFW blocklist management

292
11
Last commit: 6mo ago

Lightweight PHP dashboard that converts Fail2Ban logs into searchable JSON reports and centralizes UFW-based blocklist control with HTTPS-based multi-server sync.

Alternative to:
Fail2Ban
Fail2Ban
Mistborn

Mistborn

Multi-source threat intelligence and IOC aggregation platform

Mistborn aggregates threat intelligence from multiple sources to enrich, normalize, and distribute IOCs for security analysis and incident response workflows.

Alternative to:
VirusTotal
VirusTotal
+2