Cyb3rWard0g/HELK
The Hunting ELK observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3459
- days_rel: n/a
- days_push: 823
- n_releases_24m: 0
Adoption not part of the score
3931 stars · 689 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
The Hunting ELK (HELK) is an open-source threat hunting platform built on the ELK stack (Elasticsearch, Logstash, Kibana) with advanced analytics via Apache Spark, GraphFrames, and Jupyter notebooks. It is designed primarily for research and rapid deployment of hunt platforms for testing threat hunting use cases.
Use cases
- deploy a threat hunting platform quickly
- analyze security logs with Spark and Jupyter notebooks
- build a threat hunting lab for research
- run graph analytics on security event data
- test hunting use cases against Elasticsearch data
- explore security telemetry with SQL and Kibana
When to choose
- you want a ready-made, Docker-based hunt platform for research or labs
- you need data science capabilities (Spark, GraphFrames, Jupyter) on top of an ELK stack
- you are learning or teaching threat hunting fundamentals
When to avoid
- you need a production-grade, battle-tested SIEM for large data volumes
- you require long-term support or stable releases, since the project is alpha and infrequently updated
- you only need basic log aggregation without advanced analytics
Facets
application · maturity experimental
search-engine data-visualization analytics machine-learning monitoring security analytics big-data developer-tools self-hosted threat-hunting elk-stack elasticsearch kibana logstash apache-spark jupyter-notebook security-analytics hunt-platform docker linux
1 source
- readme: https://github.com/Cyb3rWard0g/HELK · fetched 2026-08-28 · a25245c67954
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Cyb3rWard0g/HELK | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="Cyb3rWard0g/HELK")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem