Ross ROSS = Recommend OSS · open-source software intelligence for agents

Cyb3rWard0g/HELK

The Hunting ELK observed · 2026-08-28

github.com/Cyb3rWard0g/HELK · Jupyter Notebook · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3459
  • days_rel: n/a
  • days_push: 823
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

3931 stars · 689 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

The Hunting ELK (HELK) is an open-source threat hunting platform built on the ELK stack (Elasticsearch, Logstash, Kibana) with advanced analytics via Apache Spark, GraphFrames, and Jupyter notebooks. It is designed primarily for research and rapid deployment of hunt platforms for testing threat hunting use cases.

Use cases

  • deploy a threat hunting platform quickly
  • analyze security logs with Spark and Jupyter notebooks
  • build a threat hunting lab for research
  • run graph analytics on security event data
  • test hunting use cases against Elasticsearch data
  • explore security telemetry with SQL and Kibana

When to choose

  • you want a ready-made, Docker-based hunt platform for research or labs
  • you need data science capabilities (Spark, GraphFrames, Jupyter) on top of an ELK stack
  • you are learning or teaching threat hunting fundamentals

When to avoid

  • you need a production-grade, battle-tested SIEM for large data volumes
  • you require long-term support or stable releases, since the project is alpha and infrequently updated
  • you only need basic log aggregation without advanced analytics

Facets

application · maturity experimental

search-engine data-visualization analytics machine-learning monitoring security analytics big-data developer-tools self-hosted threat-hunting elk-stack elasticsearch kibana logstash apache-spark jupyter-notebook security-analytics hunt-platform docker linux

1 source

Member repositories

RepositoryRoleHealth v2
Cyb3rWard0g/HELKmain23

For agents

markdown · JSON · MCP: product_card(name="Cyb3rWard0g/HELK")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem