Open source SIEM & security monitoring for Linux
You can't respond to what you can't see. Most security monitoring tools were built for Windows environments; Linux support is limited, detection rules are shallow and the result is a dangerous blind spot in your most critical infrastructure.
Kangasec delivers continuous, 24/7 security monitoring for Linux & open source environments, built on a fully open source stack. MITRE ATT&CK aligned. Running in your own environment. No black boxes, no SaaS dependency.
What we do
-
SIEM (Security Information & Event Management)
Our reference SIEM is built on Elasticsearch, open source, powerful & already running in many organisations. We extend it with custom detection rules, MITRE ATT&CK mapping, alerting, case management and threat hunting capabilities. For organisations with licence concerns, a fully open source alternative stack is available: OpenSearch, ElastAlert 2 & Sigma rules.
-
Host-based intrusion detection
We deploy Falco for runtime security monitoring on Linux hosts & Kubernetes nodes. Falco detects unexpected behaviour at the kernel level; process execution from shared memory, unexpected network connections from a container, shell execution from a non-shell parent process. Over 1900 detection rules out of the box, extended with custom rules for your environment.
-
Network-based intrusion detection
Zeek & Suricata provide network-level visibility: forensic logging of all connections, detection of port scans, DNS tunnelling, long-running sessions, known C2 TLS fingerprints (JA3/JA4) and unusual data volumes. CrowdSec adds crowdsourced threat intelligence; if an attacker is seen anywhere in the CrowdSec community, they're blocked before they reach your infrastructure.
-
Threat intelligence integration
We enroll your organisation in MISP, the open source threat sharing platform used by NATO, CERT teams and the Centre for Cyber Security Belgium. CIRCL, the largest MISP instance, is free to join and integrates directly with Elasticsearch to enrich your SIEM data with live threat intelligence.
-
Interpretation & advice; not just alerts
Tools without interpretation are just noise. Every month, you receive a clear report explaining what happened in your environment, what was detected, what was investigated & what actions were taken or recommended. No dashboards you don't have time to read, just actionable insight.
What you get
- 24/7 security monitoring of your Linux & Kubernetes environment
- MITRE ATT&CK aligned detection and alerting
- Monthly security reports in plain language
- Threat intelligence enrichment via MISP & CCB integration
- Rapid incident response when something is detected
- Full exit strategy: OpenSearch-based alternative if Elastic licencing changes
Why open source?
Proprietary SIEM solutions are expensive, opaque and often built for Windows. Our stack; Elasticsearch, Falco, Zeek, Suricata, CrowdSec, MISP; is transparent, community-maintained and runs entirely in your own datacenter or cloud. You're not dependent on a SaaS portal that can go down, be geopolitically restricted or change its pricing overnight.
Frequently asked questions
-
What is a SIEM and do I need one?
A SIEM (Security Information & Event Management) system collects, correlates and analyses log data from across your infrastructure to detect threats and support incident response. If you're running Linux in production & don't have visibility into what's happening on those systems, you have a blind spot. NIS2 and ISO 27001 both require logging and monitoring capabilities; a SIEM is the standard way to meet those requirements.
-
What's the difference between Falco and Zeek?
Falco monitors what's happening on a host, process executions, file accesses, network connections from individual processes. Zeek monitors what's happening on the network: connections, protocols, data volumes, DNS queries. Together they give you both host-level and network-level visibility. Kangasec deploys both as complementary layers.
-
Can you integrate with our existing tools?
Yes. We integrate with your existing log sources, ticketing systems and alerting workflows. If you're already running Elasticsearch, we build on top of what you have. If you're not, we deploy a fresh stack in your environment.
-
What if we have concerns about Elastic licencing?
We maintain a fully open source alternative: OpenSearch, OpenSearch Dashboards, ElastAlert 2 and Sigma rules. This is our exit plan if Elastic changes its licence & it means you're never locked in to a single vendor, even within our own stack.
-
Is this a managed service or a project?
Both options are available. Most clients start with a managed service, we run the monitoring, you receive the reports & alerts. For organisations that want to build in-house capability, we can also deliver this as a project with training & knowledge transfer.