Suricata
Suricata is an open-source network intrusion detection, intrusion prevention and network security monitoring engine developed by OISF and its community.
- GitHub stars
- 6.7k
- Last commit
- yesterday
- Latest release
- suricata-8.0.7
- Licence
- GPL-2.0
- Self-hosted
- Yes

Suricata is an engine for network intrusion detection (IDS), intrusion prevention (IPS) and network security monitoring (NSM), developed by the Open Information Security Foundation and the Suricata community. It inspects network traffic to detect threats, can block them when run inline as an intrusion prevention system, and supports network security monitoring and threat hunting.
The README stresses why the software is built so carefully. It processes mostly untrusted input and often sits directly reachable by an attacker, so a crash in IPS mode could knock a network offline, a compromise in passive mode could expose confidential data, and missed detections could hide an intrusion. For that reason contributions go through a long QA process that includes GitHub CI checks, peer review and private QA runs with build tests, static analysis, runtime analysis with valgrind and sanitizers, and regression tests.
Suricata is written in C and licensed under GPL-2.0. The project provides a user guide, an installation guide, a developer guide, a bug tracker and a user support forum for administrators who deploy it on their own networks.
Key features
- Network intrusion detection (IDS)
- Inline intrusion prevention (IPS)
- Network security monitoring
- Extensive QA and regression testing
- User, installation and developer guides
Pricing: Free and open source under the GPL-2.0 licence.

