Intrusion detection ratings
Tools that detect attacks on a network or host.
7 intrusion detection are rated against 4 public criteria, and 7 have enough evidence for a letter grade. Of the 3 with a known jurisdiction, 3 are based in a Five Eyes country, and 3 in the wider Fourteen Eyes.
Open-source intrusion detection only · Criteria for this category · Suggest an addition · Markdown
| Name | Grade | Score | Data | Jurisdiction | Open source | No trackers or telemetry | No ads or data sales | Independent audit |
|---|---|---|---|---|---|---|---|---|
A wireless network detector, sniffer and wireless intrusion detection system for Wi-Fi, Bluetooth, Zigbee and other radio protocols, running on Linux and macOS. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
A Linux tool that monitors which programs connect to the internet and records when they connect, how much data they transfer and to where. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
An open source host-based intrusion detection system that performs log analysis, file integrity checking, rootkit detection, real-time alerting and active response. |
Grade D | 50 | 100% | – | Yes | No | Yes | No |
Linux distribution for threat hunting, network security monitoring and log management that bundles tools such as Suricata, Zeek and Elasticsearch with its own web console. |
Grade D | 50 | 100% | United States Five Eyes | Yes | No | Yes | No |
Network intrusion detection and prevention engine and network security monitoring tool that inspects traffic against rule sets and logs protocol events and alerts. |
Grade D | 50 | 100% | United States Five Eyes | Yes | No | Yes | No |
Security platform for threat detection, integrity monitoring, log analysis, vulnerability detection and compliance, using agents on endpoints that report to a central server and dashboard. |
Grade D | 50 | 100% | – | Yes | No | Yes | No |
A commercial log management suite whose agents collect operating system audit and event logs and forward them to a central server for analysis and compliance reporting. |
Grade F | 20 | 100% | Australia Five Eyes | No | No | Yes | No |
Questions
What is the most private option among intrusion detection?
No pick has been made yet. The table above is sorted by score, based on public evidence.
How are intrusion detection rated?
Each entry answers 4 questions: open source, no trackers or telemetry, no ads or data sales and independent audit. Answers need links to evidence. See the full criteria.
Does jurisdiction matter?
Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.