7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

2 alternatives ranked by real activity

Open-source Darktrace alternatives

A curated, ranked list of the 2 best open-source alternatives to Darktrace.

The best open-source alternative to Darktrace is Suricata. If that doesn't suit you, another good option is Security Onion.

Darktrace alternatives are mainly security tools. 2 of them shipped code in the last 30 days, 2 can be self-hosted, and none uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Suricata

Suricata is an open-source network intrusion detection, intrusion prevention and network security monitoring engine developed by OISF and its community.

GitHub stars
6.7k
Last commit
yesterday
Latest release
suricata-8.0.7
Licence
GPL-2.0
Self-hosted
Yes
suricata.ioSuricata homepage screenshot

Suricata is an engine for network intrusion detection (IDS), intrusion prevention (IPS) and network security monitoring (NSM), developed by the Open Information Security Foundation and the Suricata community. It inspects network traffic to detect threats, can block them when run inline as an intrusion prevention system, and supports network security monitoring and threat hunting.

The README stresses why the software is built so carefully. It processes mostly untrusted input and often sits directly reachable by an attacker, so a crash in IPS mode could knock a network offline, a compromise in passive mode could expose confidential data, and missed detections could hide an intrusion. For that reason contributions go through a long QA process that includes GitHub CI checks, peer review and private QA runs with build tests, static analysis, runtime analysis with valgrind and sanitizers, and regression tests.

Suricata is written in C and licensed under GPL-2.0. The project provides a user guide, an installation guide, a developer guide, a bug tracker and a user support forum for administrators who deploy it on their own networks.

Key features

  • Network intrusion detection (IDS)
  • Inline intrusion prevention (IPS)
  • Network security monitoring
  • Extensive QA and regression testing
  • User, installation and developer guides

Pricing: Free and open source under the GPL-2.0 licence.

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
today
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections

Darktrace alternatives: questions

What is the best open-source alternative to Darktrace?
Suricata is the top-ranked open-source alternative to Darktrace on Enlisted: Suricata is an open-source network intrusion detection, intrusion prevention and network security monitoring engine developed by OISF and its community. Another strong option is Security Onion.
Are these Darktrace alternatives free?
Both are open source, so the code is free to use under its licence, and both can be self-hosted on your own server or computer.
How is this list of Darktrace alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 2 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all