← Back to match
sigwood
Local-first, transparent threat-hunting CLI for logs you already have — no SIEM, no agent.
Desktopfreeglobal
sigwood is a local-first, command-line threat-hunting tool for self-hosters that points at existing logs — Zeek, Pi-hole, syslog, CloudTrail — and runs named detectors for beaconing, suspicious DNS, port scans, and unusual activity, entirely on the user's own box with nothing to deploy and no data leaving the machine. It's for self-hosters and small teams who want SIEM-style threat-hunting insight without the weight of an actual SIEM.
Categories
security toolsthreat huntinglog analysis

