15 years helping South African businesses
choose better software

SIEM Tools

Security information and event management (SIEM) software applies security event management and security information management capabilities to identify potential threats and resolve security incidents. It aggregates and analyzes data from network servers, devices, domain controllers, and more. It also helps users store, normalize, aggregate, and apply analytics to these data to discover trends.

Featured software

84 results

Versatile Log & Event Log Hybrid SIEM solution with Active Directory, Health & Inventory monitoring - supports NIST & CMMC.compliance. Learn more about EventSentry
Hybrid SIEM solution combining real-time (event) log monitoring with FIM, SW/HW inventory and more for an integrated approach to increase network security. Unique security event log normalization & correlation engine with descriptive email alerts provides additional context and presents cryptic Windows security events in easy to understand reports that offer insight beyond what's available from raw events. A dynamic release cycle constantly adds features for timely challenges like Ransomware. Learn more about EventSentry

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
EventLog Analyzer brings log management, security auditing, threat detection and mitigation, and compliance management in one console. Learn more about ManageEngine EventLog Analyzer
EventLog Analyzer goes beyond log management to bring together security auditing, threat detection and mitigation and compliance management in one console. With real-time security auditing and end-to-end incident management capabilities, EventLog Analyzer helps organizations to prioritize high-risk security threats and stop cyberattacks. The solution helps organizations overcome network security challenges and strengthen their cybersecurity posture. Learn more about ManageEngine EventLog Analyzer

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
A re-imagined SecOps toolkit equipped with built-in hunting and action capabilities, managed from a single, unified interface. Learn more about Heimdal Threat-hunting & Action Center
The Heimdal Threat-hunting and Action Center brings a re-imagined SecOps toolkit under one roof. It provides security teams with an advanced threat and risk-centric view of their entire IT landscape, offering granular telemetry across endpoints and networks for swift decision-making. Furthermore, the platform is equipped with built-in hunting and action capabilities, which can be easily managed from a single, unified interface straight out of the box. Learn more about Heimdal Threat-hunting & Action Center

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Log360 is a comprehensive SIEM solution that helps you combat threats on premises, in the cloud, or in a hybrid environment. Learn more about ManageEngine Log360
Log360 is a SIEM solution that helps organizations of all sizes combat threats on premises, in the cloud, or in a hybrid environment. You can customize the solution for your unique use cases by using its threat intelligence, event correlation, file integrity monitoring, and user activity monitoring capabilities. You can monitor activities that occur in your Active Directory, network devices, employee workstations, file servers, Microsoft 365, cloud services and more. Learn more about ManageEngine Log360

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Firewall Analyzer, a log analytics and configuration management software for a complete visibility over entire network security. Learn more about ManageEngine Firewall Analyzer
Firewall Analyzer is an agent less log analytics and configuration management software, which analyzes logs from firewalls and generates real time alert notifications, security and bandwidth reports. The solution is a vendor-agnostic software and supports more than 50 plus firewall vendors. It also empowers administrators by providing comprehensive reports about the security events and in turn they can take steps to mitigate the security. Learn more about ManageEngine Firewall Analyzer

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Cloud-based service that allows you to create anything from simple websites to complex applications for businesses of all sizes.
Google Cloud Platform is cloud-based service that allows you to create anything from simple websites to complex applications for businesses of all sizes in all industries. Google Cloud Platform offers a scalable data warehouse powered by cloud storage and machine learning, as well as relational databases for transactions, complex queries, and more. New customers get $300 in free credits during the first 90 days after exhausting free usage which is available across 20+ different products. Learn more about Google Cloud

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Datadog provides an easy-to-use cloud-native SIEM with out-of-the-box security integrations and customizable threat detection rules.
Datadog Security Monitoring, a part of the Datadog Cloud Security Platform, provides robust threat detection for dynamic, cloud-scale environments. With Security Monitoring, you can analyze operational and security logs in real time—regardless of their volume—while utilizing curated, out-of-the-box integrations and rules to detect threats. Developers, security, and operations teams can also leverage detailed observability data to accelerate security investigations in a single, unified platform. Learn more about Datadog

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Ingest data from multicloud/on-premises to detect threats with advanced security analytics, ML & threat intelligence.
Splunk SIEM is a comprehensive security analytics platform that gives businesses the insights needed to stay secure and protected. With data-driven insights, businesses can combat threats, protect data, and mitigate risk at scale with analytics they can act on. The platform breaks down data silos, allowing businesses to ingest data from multicloud and on-premises deployments and gather full visibility to quickly detect malicious threats. Learn more about Splunk Enterprise

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
The JumpCloud Directory Platform reimagines the directory as a complete platform for identity, access, and device management.
JumpCloud’s cloud directory enables internal IT departments, MSPs, VARs/distributors, and DevOps teams to securely and easily enable access to any IT resource, from anywhere. Get insight into activity log data for all of JumpCloud’s endpoints and easily ingest it into SIEM tools for auditing and compliance purposes. Track cross-OS system usage, RADIUS network authentications, LDAP access, SAML SSO usage, and changes made by admins to end-user identities and privileges. Learn more about JumpCloud Directory Platform

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time.
Built on a foundation of free and open, Elasticsearch, Logstash, Kibana, and Beats pave the way for diverse use cases that start with logging and span as far as your imagination takes you. Elastic features like machine learning, security, and reporting compound that value — and since they’re made for Elastic, you'll only find them from us. Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time. Learn more about Elastic Stack

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Cloud-based mobile endpoint security platform that helps firms with preventing compromise of corporate data and phishing.
Lookout, Inc. is the endpoint to cloud security company purpose-built for the intersection of enterprise and personal data. We safeguard data across devices, apps, networks and clouds through our unified, cloud-native security platform. Learn more about Lookout

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Logz.io is the leading open source-based cloud observability platform.
Logz.io is the leading cloud observability platform that enables engineers to use the best open source tools in the market without the complexity of operating, managing, and scaling them. Logz.io offers three products: Log Management built on ELK, Infrastructure Monitoring based on Grafana, and an ELK-based Cloud SIEM. These are offered as fully managed service designed to help engineers monitor, troubleshoot and secure their distributed cloud workloads more effectively. Learn more about Logz.io

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Graylog is a leading centralized log management solution to capture, store and enable real-time analysis of terabytes of machine data.
Graylog is a leading centralized log management solution for capturing, storing and enabling analysis of petabytes of machine data. Purpose-built for modern log analytics, Graylog removes complexity from data exploration, compliance audits, and threat hunting so you can quickly and easily find meaning in data and take action faster. Select the right log management solution right option to fit your needs: - Graylog Enterprise - Graylog Cloud - Graylog Small Business - Graylog Open Learn more about Graylog

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Sematext gives businesses full-stack visibility by exposing logs, metrics, real user & synthetic data and traces through a single Cloud
Sematext Cloud is an all-in-one observability solution for software-based companies that provides key insights into front-end and back-end performance. Sematext encompasses infrastructure, real user & synthetic monitoring, transaction tracing, and log management. Sematext Cloud also offers flexible app-scoped pricing based on plan, volume, and retention selection, where each App can have a different plan, volume, and retention, giving you lots of control over costs with no overage fees. Learn more about Sematext Cloud

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Intelligent solution that monitors your network in order to detect and prioritize threats through machine learning and AI algorithms.
Intelligent solution that monitors your network in order to detect and prioritize threats through machine learning and AI algorithms. Learn more about IBM Security QRadar

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Sumo Logic delivers the only cloud-native, real-time machine data analytics platform that provides continuous intelligence.
Sumo Logic is a cloud security analytics platform that provides security intelligence for your microservices, hybrid and multi-cloud environment. Sumo Logic can be your first cloud SIEM, replace your legacy SIEM, or co-exist with your existing SIEM solution. Sumo Logic delivers the only cloud-native, real-time machine data analytics platform that provides continuous intelligence. Learn more about Sumo Logic

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Enable capabilities such as endpoint protection, SIEM, vulnerability management, threat hunting, and more all within one console.
EventTracker, our flagship managed security platform, is architected to scale with organizations of any size and any stage of maturity. Whether you need a targeted supplement to your existing capabilities and staff or a complete outsourced solution, the EventTracker platform is uniquely customizable to your needs. EventTracker's “snap-in” architecture lets you enable capabilities such as endpoint protection, SIEM, vulnerability management, threat hunting, and more all within one console. Learn more about Netsurion

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SIEM tool that monitors logs, detect and prevent breaches with predefined corelations and alerts.
SureLog Security Information and Event Management (SIEM) platform analyzes log event data in real time to detect and prevent security attacks. By consolidating events from all log sources, SureLog correlates and aggregates events into normalized alerts to spot cyber security threats and instantly notifies your IT & security teams. SureLog SIEM is available on premises and in a cloud environments Learn more about Surelog

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Unified Security Operation Platform simplifies Secops by offering a single, integrated solution with next-gen SIEM, TI, UEBA, and TDIR.
Logsign Unified SO Platform integrates next-gen SIEM, threat intelligence, UEBA, and SOAR and empowers organizations to optimize and streamline their cybersecurity operations. In addition to that, the platform offers seamless integration capabilities, allowing them to effortlessly integrate their existing security software and leverage our vast integration library, expanding the Logsign USO Platform's functionality and providing a comprehensive security management experience. Learn more about Logsign

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
A log data management solution that centrally records and manages logs of various IT systems with unique log translation technology.
The "ALog series", which has been installed with more than 5,100 contracts in Japan and overseas, is a log data management solution that centrally records and manages logs of various IT systems. With the motto "Make difficult security easy", there are many features that help log utilization, such as unique log translation technology, abundant report templates, and detection of internal fraud by AI. With these technologies, you can realize advanced log utilization without specialized knowledge. Learn more about ALog Series

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Security management platform offering fully integrated security controls for threat detection and compliance management.
USM Anywhere delivers a unified, simple and affordable solution for threat detection and compliance. Powered by the latest AlienVault Labs Threat Intelligence and the Open Threat Exchange the largest crowd-sourced threat intelligence exchange, USM enables mid-size organizations to defend against modern threats. Learn more about USM Anywhere

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Unify SIEM, endpoint security, and cloud security Elastic Security modernizes security operations — enabling analytics across years of
Unify SIEM, endpoint security, and cloud security Elastic Security modernizes security operations — enabling analytics across years of data, automating key processes, and bringing native endpoint security to every host. Elastic Security equips teams to prevent, detect, and respond to threats at cloud speed and scale — securing business operations with a unified, open platform. Learn more about Elastic Security

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
User behavior analytics and vulnerability management solution that helps identify internal and external threats.
User behavior analytics and vulnerability management solution that helps identify internal and external threats. Learn more about ArcSight

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
An easy, effective XDR platform for small and medium businesses, helping them detect and respond to cybersecurity threats.
Blumira’s mission is to help SMBs and mid-market companies detect and respond to cybersecurity threats faster to stop breaches and ransomware. Blumira’s all-in-one SIEM+XDR platform combines logging with automated detection and response for better security outcomes and consolidated security spend. Blumira’s Free SIEM edition allows you to gain visibility into your environment within minutes for up to 3 integrations Learn more about Blumira

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Logpoint's SIEM+SOAR & UEBA platform helps businesses protect their infrastructure from breaches & efficiently respond to cyberattacks
Logpoint is the creator of a reliable, innovative cybersecurity operations platform — empowering organizations to thrive in a world of evolving threats. By combining sophisticated technology and a profound understanding of customer challenges, Logpoint bolsters security teams’ capabilities while helping them combat current and future threats. Logpoint offers SIEM, UEBA, SOAR and SAP security technologies converged into a complete platform that efficiently detects and respond to threats. Learn more about LogPoint

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Cybersecurity management tool that helps businesses detect & overcome cyber threats through machine-based analytics, UEBA & more.
Cybersecurity management tool that helps businesses detect & overcome cyber threats through machine-based analytics, UEBA & more. Learn more about LogRhythm Log Management

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SIEM solution that helps businesses with performance, security, and availability monitoring to detect and remediate security threats.
SIEM solution that helps businesses with performance, security, and availability monitoring to detect and remediate security threats. Learn more about FortiSIEM

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Managed security platform that includes monitoring and management of security infrastructure around the clock.
SilverSky Managed Security Services monitors and manages your UTM devices, servers and endpoints around the clock giving you peace of mind that your devices are continually updated and patched and your organization is monitored by our expert Security Operations Center analysts. SilverSky is uniquely qualified to help small and mid-sized businesses in regulated industries meet their security and compliance needs. Learn more about SilverSky Managed Security Services

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Security Information & Event Management (SIEM) designed exclusively for MSSPs. Complete SIEM, 24/7 SOC and multi-tenancy set up.
Vijilan is a security monitoring company that alerts IT organizations and Managed Services Providers (MSPs) when a potential security breach taking place in their organization or customers environment. Vijilan's continuous monitoring operates in Aventura, Florida and includes threat detection and response in near real-time. Vijilan delivers the technologies, processes, and people as a service primarily through Managed Service Providers (MSPs). SIEM-SOC-IRT as one product. Learn more about Vijilan

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Full-functioned, yet affordable, SIEM virtual appliance for real-time log management, operational troubleshooting and compliance.
Delivers comprehensive Security Information and Event Management (SIEM) capabilities in a highly affordable, easy-to-deploy virtual appliance. Security Event Manager automates and simplifies the complex task of security management, operational troubleshooting, and continuous compliance, enabling IT pros to immediately identify and re-mediate threats and vital network issues before critical systems and data can be exploited. SIEM software has never been easier to use or more affordable to own! Learn more about Security Event Manager

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Software that provides a unified view of service delivery, availability, performance and security of IT applications.
ServicePilot monitoring software enables faster resolution of IT incidents. This intelligent observability platform collects and analyzes metrics, traces and logs to improve application performance and prevent IT failures. It also unifies monitoring and breaks down silos to ensure continuity of services and IT infrastructure. Learn more about ServicePilot

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Behavioural analysis tool to detect weak signals & anomalies in information systems using forensics & extensive research algorithms.
SaaS on-premise behavioural analysis engine to detect weak signals & anomalies in information systems using forensics & extensive research algorithms. Learn more about Reveelium

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM)
Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution that lets you see and stop threats before they cause harm. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. Eliminate security infrastructure setup and maintenance. Learn more about Microsoft Sentinel

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SIEM solution that helps businesses send and receive real-time information regarding malicious hosts across networks.
SIEM solution that helps businesses send and receive real-time information regarding malicious hosts across networks. Learn more about AlienVault OSSIM

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
GorillaStack helps to automate real-time security remediation, managing backup lifecycles, and optimize cloud bills.
GorillaStack is a SIEM software to get real time alerts and automate remediation for security. With automation, you can achieve compliance and governance across AWS and Azure Cloud easily. GorillaStack can also help to reduce your cloud bills and manage backups reliably. Learn more about GorillaStack

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
JupiterOne is a cloud-native security platform providing visibility security and governance to your entire cyber asset environment.
With JupiterOne, teams discover, monitor, understand, and act to secure their entire digital environment. Cloud resources, ephemeral devices, identities, ownerships, access, code, pull requests, and much more are collected, graphed, and analyzed automatically by JupiterOne. JupiterOne creates a contextual knowledge-base using graphs and relationships as the single source of truth for an organization’s security and infrastructure operations. Learn more about JupiterOne

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
All logs, all security information - whether IT or IoT. The SIEM uses the information available from the Enginsight Agent directly.
Your SIEMphony for detecting and defending against cyber attacks Enginsight SIEM (Security Information and Event Management) offers you proactive real-time protection and comprehensive security information across all data sources. Like a good symphony, all Enginsight software components play together and automatically enrich the SIEM with information from the area of attack detection. This allows you to create not just reactive logging, but proactive security. Learn more about Enginsight

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
A horizontally scalable SIEM solution that lets you handle structured-unstructured logs, query faster and perform high speed analytics.
DNIF deploys pre-built SIEM rules to detect known attacks effortlessly. It learns from trend profiles to handle unknown attacks. It augments your existing SIEM with automation and capacity. It builds logic to detect any deviation in the wild and identifies cause using machine learning models designed to attribute risk. It can ingest logs from all types of devices. All components are designed to scale up and down seamlessly without breaking operations either by load balancing or by clustering. Learn more about DNIF HYPERCLOUD

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Delivers actionable intelligence and integrations required for you to prioritize, investigate, and respond to threats.
Delivers actionable intelligence and integrations required for you to prioritize, investigate, and respond to threats. Learn more about McAfee SIEM

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SIEM solution that helps organizations identify, investigate and resolve threats.
SIEM solution that helps organizations identify, investigate and resolve threats. Learn more about Enterprise Security Manager

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Exabeam helps security teams outsmart the odds by adding intelligence to their existing security tools.
Exabeam helps security teams outsmart the odds by adding intelligence to their existing security tools – including SIEMs, XDRs, cloud data lakes, and hundreds of other business and security products. Out-of-the-box use case coverage repeatedly delivers successful outcomes. Behavioral analytics allows security teams to detect compromised and malicious users that were previously difficult, or impossible, to find. Learn more about Exabeam

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
A Dynamic Threat Detection and Response Platform
MixMode is the leader in delivering AI cybersecurity solutions at scale. MixMode offers a patented, self-supervised learning Platform designed to detect known and unknown threats in real-time across cloud, hybrid, or on-prem environments. Large enterprises with big data environments, including global entities in financial services, fortune 1K commercial enterprises, critical infrastructure, and government sectors, trust MixMode to protect their most critical assets. Learn more about MixMode

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SOC Prime TDM is a cross-platform SaaS community offering threat detection content that is easily convertible to various SIEM formats.
SOC Prime Threat Detection Marketplace® (TDM) is a SaaS content platform that aggregates over 65,000 SIEM & EDR rules, parsers and search queries, Snort and YARA rules designed to work directly in the company¿s preferred SIEM environment, including Microsoft Azure Sentinel, Sumo Logic, Humio, the Elastic Stack, Splunk, ArcSight, QRadar, and more. TDM also delivers content using Sigma, a generic signature format, which can be used across various SIEM systems and streamed via an API on the fly. Learn more about Threat Detection Marketplace

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
InsightIDR is your threat detection & response solution. Find & respond to all of the top attack vectors behind breaches.
InsightIDR is your threat detection & response solution. Find & respond to all of the top attack vectors behind breaches: phishing, malware, and the use of stolen passwords. InsightIDR natively collects data from your endpoints, security logs, & cloud services. Apply user and attacker behavior analytics to your data to find intruder activity at each step of the attack chain. Unify your security data. Detect before things get critical. Respond 20x faster with visual investigations & automation. Learn more about InsightIDR

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Fortra's Event Manager is a cybersecurity insight and response platform that ensures critical events get the attention they require.
Fortra's Event Manager is a cybersecurity insight and response platform that ensures critical events get the attention they require. Events are translated into an easy-to-interpret format, and critical events are separated from the noise in real time. This enables security analysts to act quickly and decisively, even without specialized knowledge of every technology in your environment. A full audit trail makes it easy to meet compliance requirements. Learn more about Event Manager

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Panther Labs provides a highly scalable and refreshingly practical platform for threat detection and response.
Panther Labs was founded by a team of veteran security practitioners who faced the challenges of security operations at scale and set out to build a platform to solve them. The result is Panther, a refreshingly practical platform for threat detection and response powered by a highly scalable security data lake and detection-as-code. Panther gives security teams the power to detect any breach, anywhere and is trusted by customers like Snowflake, Dropbox, Zapier, and more. Learn more about Panther

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
Make decisive, appropriate responses to incidents by automating identification and resolution processes.
Make decisive, appropriate responses to incidents by automating identification and resolution processes. Learn more about Sentinel

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
TEHTRIS XDR | SIEM collects, processes, and alerts your events to facilitate your decision-making.
TEHTRIS XDR | SIEM collects, processes, and alerts your events to facilitate your decision-making. Whatever your sources and their formats (Syslog, Leef, CEF, JSON, CSV, KVP, XML...), TEHTRIS SIEM collects logs thanks to a library of parsers and connectors that are constantly evolving. Analyze all your events automatically and choose from a catalog of over 2 000 security rules. In addition, take advantage of the behavioral analysis engine (UEBA) to identify unusual activities on your IT assets. Learn more about TEHTRIS XDR Platform

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
NetWitness Platform is cybersecurity software for threat detection, investigation, and response.
NetWitness Platform is a security information and event management software that provides threat detection, investigation, and response capabilities. The comprehensive platform collects and analyzes data across multiple sources to detect threats, and includes orchestration and automation features to help security teams respond faster. Learn more about NetWitness

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs
SaaS and on-premise enterprise software solution for smarter and easier DevSecOps & ITSM operations.
Versio.io is a SaaS and on-premise enterprise software platform for smarter and easier DevSecOps & ITSM operations. The following solutions are provided by Versio.io: - Asset and Configuration Inventory (CMDB) - Change Management - Product release and patch management - IT vulnerabilities detection - IT governance - Enterprise architecture analysis & management Versio.io is used in data centers, (multi-) cloud environments and for SaaS applications. Learn more about Versio.io

Features

  • Log Management
  • Behavioral Analytics
  • Real Time Monitoring
  • Application Security
  • Threat Intelligence
  • Endpoint Management
  • Event Logs