7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Suricata

Open source

Suricata is an open-source network intrusion detection, intrusion prevention and network security monitoring engine developed by OISF and its community.

suricata.io
Suricata homepage screenshot
GitHub stars
6.7k
Last commit
yesterday
Repository age
14 years
Version
suricata-8.0.7
Licence
GPL-2.0
Self-hosted
Yes

About Suricata

Suricata is an engine for network intrusion detection (IDS), intrusion prevention (IPS) and network security monitoring (NSM), developed by the Open Information Security Foundation and the Suricata community. It inspects network traffic to detect threats, can block them when run inline as an intrusion prevention system, and supports network security monitoring and threat hunting.

The README stresses why the software is built so carefully. It processes mostly untrusted input and often sits directly reachable by an attacker, so a crash in IPS mode could knock a network offline, a compromise in passive mode could expose confidential data, and missed detections could hide an intrusion. For that reason contributions go through a long QA process that includes GitHub CI checks, peer review and private QA runs with build tests, static analysis, runtime analysis with valgrind and sanitizers, and regression tests.

Suricata is written in C and licensed under GPL-2.0. The project provides a user guide, an installation guide, a developer guide, a bug tracker and a user support forum for administrators who deploy it on their own networks.

Key features

  • Network intrusion detection (IDS)
  • Inline intrusion prevention (IPS)
  • Network security monitoring
  • Extensive QA and regression testing
  • User, installation and developer guides

Good fit for

  • →Monitoring network traffic for threats
  • →Blocking malicious traffic inline
Built with
C
Tags
ids
ips
nsm
network-security
intrusion-detection
threat-hunting
security
c-language

Suricata: questions and answers

What is Suricata used for?
Suricata is an open-source network intrusion detection, intrusion prevention and network security monitoring engine developed by OISF and its community. It is a good fit for monitoring network traffic for threats and blocking malicious traffic inline.
Is Suricata open source?
Yes. Suricata is open source under the GPL-2.0 licence. Its source code is on GitHub at OISF/suricata and is written mainly in C.
Is Suricata free?
Yes. Suricata is open source, so the software itself is free to use.
Can I self-host Suricata?
Yes. Suricata can be self-hosted on your own server or infrastructure; there is no official hosted version.
What is Suricata an alternative to?
Suricata is an open-source alternative to Palo Alto Networks, Fortinet, Darktrace and Check Point. Other open-source alternatives to Palo Alto Networks include OPNsense, pfSense and Kubescape.
Is Suricata actively maintained?
Yes. The most recent commit to Suricata was on 1 October 2026. The project has 6.7k stars on GitHub.

Open-source alternatives to Suricata

See all

SaaS alternatives to Suricata

See all