{"repo":"GACWR/OpenUBA","free":true,"listed":false,"github":"https://github.com/GACWR/OpenUBA","clone":"git clone https://github.com/GACWR/OpenUBA.git","description":"A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [BETA]","language":"Python","stars":509,"topics":["ueba","datascience","cybersecurity","analytics","threathunting","tensorflow","spark","information-security","siem","anomaly-detection"],"license":"Apache-2.0","category":"analytics","readme_excerpt":"Open User Behavior Analytics (v0.0.2) A robust, flexible, and lightweight open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. Status Badge Status Badge --- --- --- --- Build License Issues Closed Issues Pull Requests Last Commit Top Language Code Size Repo Size Contributors Stars Forks Releases Platform Python TypeScript FastAPI Next.js PostgreSQL Kubernetes Docker Spark Elasticsearch PRs Welcome Chat --- Table of Contents - Problem - Solution - Architecture - Tech Stack - Features - Rule Canvas - Model Library - Model Execution Sandbox - Workspaces & SDK - Authentication and Access Control - LLM Assistant - Getting Started - Development - Makefile Reference - Testing - White Paper - Community - License --- Problem Many UBA platforms typically use a \"black box\" approach to data science practices, which may work best for security analysts who are not interested in the nuts and bolts of the underlying models being used to generate anomalies, baselines, and cases. These platforms view their models as IP. Solution OpenUBA takes an \"open-model\" approach, and is designed for the small subset of security analysts who have authentic curiosity about what models are doing, and how they work under the hood. We believe in the scientific computing community, and its contributions over the years (libraries, toolkits, etc). In security, rule/model transparency i","default_branch":null,"files":null,"tree":[],"storefront":"/r/GACWR","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/GACWR/OpenUBA/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}