tirreno

tirreno

Security analytics framework for in-app threat detection and risk

953stars
100forks
Last commit: 1mo ago
Repo age: 2y old
tirreno screenshot

tirreno is an open-source security analytics framework that helps teams monitor and protect applications from threats, fraud, bots, and account takeovers using in-app telemetry. It ingests application events and turns them into actionable dashboards, investigations, and decisions focused on user behavior and business-logic abuse.

Key Features

  • Event tracking and ingestion via API calls for application security telemetry
  • Near real-time monitoring to detect suspicious behavior inside the product
  • Single-user view with activity timelines, sessions, connected identities, and risk signals
  • Rule-based risk assessment to flag and score risky events and behaviors
  • Case management and automated actions (for example, suspend or send to review)
  • Field-level audit trail to track what changed, when, and by whom for key data
  • Designed for extensibility with minimal dependencies and a small attack surface

Use Cases

  • Detect and investigate account takeover, credential stuffing, and anomalous logins
  • Identify bots, scraping, and business-logic abuse that bypass perimeter defenses
  • Maintain detailed audit trails and user activity history for compliance and forensics

Limitations and Considerations

  • Storage needs can grow quickly with high event volume (approximately several GB per million events in PostgreSQL)

tirreno fits teams that want security visibility at the application layer rather than only at the network perimeter. With a lightweight PHP/PostgreSQL stack and a focus on user-centric analytics, it can act as a security backbone for many kinds of products and internal systems.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

30k
2.4k
Last commit: 4d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.1k
1.3k
Last commit: 2mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

16.6k
1.4k
Last commit: 15d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.2k
567
Last commit: 18h ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Graylog

Graylog

Centralized log management and analysis platform

7.9k
1.1k
Last commit: 1d ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.4k
307
Last commit: 20h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19