Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Suricata

High-performance IDS/IPS and network security monitoring with multi-threading, TLS inspection options, and Lua scripting.

Why it is included

OISF-backed engine widely deployed beside Zeek for signature and protocol-aware detection.

Best for

SOC stacks, SPAN/TAP monitoring, and inline prevention where policy allows.

Strengths

  • IPS mode
  • Eve JSON
  • Emerging Threats rules ecosystem

Limitations

  • Hardware sizing and TLS inspection have operational cost

Good alternatives

Snort · Zeek

Related tools