Security Analytics tools

27 tools filed under Security Analytics, in 4 categories. Open a profile for verified pricing, features and alternatives.

Bot detection & web fraud

Tool Pricing model Free tier Open source
Arkose Labs Fraud and bot prevention platform built around adaptive, multi-generation CAPTCHA-style challenges plus device, email, and AI-agent risk signals. Quote only No No
Castle Usage-priced fraud and bot API that scores every login, registration, and transaction using device, behavioral, IP, and email signals. Usage-based Yes No
Cloudflare Bot Management Edge-native bot mitigation built into Cloudflare's network, combining machine learning, behavioral analysis, and the Turnstile CAPTCHA alternative. Quote only Yes No
DataDome Bot and fraud protection platform that scores traffic in real time using layered device fingerprinting, behavioral analysis, and machine learning. Quote only No No
HUMAN Security Bot and fraud prevention platform whose Human Verification Engine issues human-or-not decisions from layered technical and behavioral signals. Quote only No No
Kasada Bot and fraud defense platform that uses dynamic, polymorphic JavaScript and proof-of-work challenges instead of CAPTCHAs to detect automation. Quote only No No
Netacea Server-side bot and agent management platform that classifies traffic from network logs rather than client-side JavaScript. Quote only No No

Log analytics

Tool Pricing model Free tier Open source
Elasticsearch Distributed search and analytics engine underlying the ELK stack, used for log analytics, full-text search and, via Elastic Security, SIEM. Usage-based Yes No
Splunk Long-established platform for indexing and searching machine data at scale, used for both IT log analytics and SIEM. Quote only No No

Security analytics & SIEM

Tool Pricing model Free tier Open source
CrowdStrike Falcon LogScale Index-free log management engine (formerly Humio) now sold by CrowdStrike as the data backbone for its Next-Gen SIEM. Quote only No No
Devo Cloud-native SIEM and data analytics platform emphasizing real-time query performance at high ingest volume. Quote only No No
Exabeam SIEM/security analytics platform built around behavioral baselining (UEBA) to surface anomalous user and entity activity. Quote only No No
Google Security Operations Google Cloud's SIEM, built on the Chronicle backend, offering high-volume, long-retention log search with integrated threat intelligence. Quote only No No
IBM QRadar Long-established enterprise SIEM offering log correlation, UEBA and SOAR, now offered as SaaS or on-premises appliances. Quote only No No
Microsoft Sentinel Cloud-native SIEM and SOAR built on Azure Log Analytics, billed per GB ingested per day with optional commitment discounts. Usage-based No No
Panther Cloud-native, detection-as-code SIEM built on a Snowflake-style data lake for security teams that prefer writing detections as code. Quote only No No
Rapid7 InsightIDR Cloud SIEM/XDR from Rapid7 combining log search, UEBA and endpoint detection, priced per monitored asset rather than per GB. Quote only No No
Securonix Cloud-native SIEM built on a Snowflake data lake, emphasizing behavior analytics and content-rich threat detection. Quote only No No
Wazuh Free, open-source security platform combining SIEM and XDR capabilities for log analysis, threat detection and compliance. Open source + paid Yes Yes

Threat intelligence

Tool Pricing model Free tier Open source
Censys Internet-wide scanning platform that maps public-facing infrastructure for attack-surface management and adversary-infrastructure tracking. Quote only Yes No
Flashpoint Threat-intelligence platform built on primary-source data collected from underground forums, marketplaces, and adversary communities. Quote only No No
Google Mandiant Frontline threat-intelligence and incident-response practice, now part of Google Cloud, built on data from its own breach investigations. Quote only No No
Google VirusTotal Aggregates verdicts from dozens of antivirus engines and blocklist services on submitted files and URLs, now operated by Google. Free tier + paid Yes No
GreyNoise Classifies internet-wide scanning traffic as benign, malicious, or unknown so SOC teams can filter background noise out of alerts. Free tier + paid Yes No
Intel 471 HUMINT-driven cybercrime intelligence platform built on analysts' direct engagement inside closed criminal communities. Quote only No No
LevelBlue Open Threat Exchange Free, community-contributed threat-intelligence platform of shared indicators of compromise, now operated by LevelBlue. Free Yes No
Shodan Search engine that indexes internet-connected devices and services by crawling the entire internet, used both defensively and offensively. Subscription Yes No