Matchboxmatchbox
← Back to match

sigwood

Local-first, transparent threat-hunting CLI for logs you already have — no SIEM, no agent.

Desktopfreeglobal

sigwood is a local-first, command-line threat-hunting tool for self-hosters that points at existing logs — Zeek, Pi-hole, syslog, CloudTrail — and runs named detectors for beaconing, suspicious DNS, port scans, and unusual activity, entirely on the user's own box with nothing to deploy and no data leaving the machine. It's for self-hosters and small teams who want SIEM-style threat-hunting insight without the weight of an actual SIEM.

Categories
security toolsthreat huntinglog analysis

Full match profile

Behind the summary, Matchbox keeps a richer profile of sigwood - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether sigwood (or something else) actually fits.