tirreno

tirreno

Security analytics framework for in-app threat detection and risk

1.1kstars
114forks
Last commit: 13d ago
Repo age: 2y old
tirreno screenshot

tirreno is an open-source security analytics framework that helps teams monitor and protect applications from threats, fraud, bots, and account takeovers using in-app telemetry. It ingests application events and turns them into actionable dashboards, investigations, and decisions focused on user behavior and business-logic abuse.

Key Features

  • Event tracking and ingestion via API calls for application security telemetry
  • Near real-time monitoring to detect suspicious behavior inside the product
  • Single-user view with activity timelines, sessions, connected identities, and risk signals
  • Rule-based risk assessment to flag and score risky events and behaviors
  • Case management and automated actions (for example, suspend or send to review)
  • Field-level audit trail to track what changed, when, and by whom for key data
  • Designed for extensibility with minimal dependencies and a small attack surface

Use Cases

  • Detect and investigate account takeover, credential stuffing, and anomalous logins
  • Identify bots, scraping, and business-logic abuse that bypass perimeter defenses
  • Maintain detailed audit trails and user activity history for compliance and forensics

Limitations and Considerations

  • Storage needs can grow quickly with high event volume (approximately several GB per million events in PostgreSQL)

tirreno fits teams that want security visibility at the application layer rather than only at the network perimeter. With a lightweight PHP/PostgreSQL stack and a focus on user-centric analytics, it can act as a security backbone for many kinds of products and internal systems.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

32.1k
2.5k
Last commit: 25d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.8k
1.3k
Last commit: 3mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

17k
1.5k
Last commit: 13d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.6k
576
Last commit: 1d ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Graylog

Graylog

Centralized log management and analysis platform

8k
1.1k
Last commit: 8h ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.5k
323
Last commit: 12h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19