# matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Repository: https://github.com/matanolabs/matano
Canonical: https://ross.abutalabs.com/products/matano
Homepage: https://matano.dev
Language: Rust
License: Apache-2.0
License Family: permissive
Topics: aws, cloud, security, big-data, serverless, apache-iceberg, log-analytics, log-management, threat-hunting, rust, alerting, cloud-native, aws-security, cloud-security, cybersecurity, secops, security-tools, dfir, detection-engineering, siem
Last push: 2025-01-08T04:14:13+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1522, "days_push": 602, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1694, forks 122 (observed 2026-08-28T04:05:23.577607+00:00)

## What it is
Matano is an open-source, cloud-native security data lake that runs in your AWS account, normalizing unstructured security logs into a structured, queryable lake built on Apache Iceberg. It provides realtime detection-as-code in Python with Sigma rule import, VRL-based log transformation pipelines, and integrations with 50+ log sources at petabyte scale.

## Use cases
- build a security data lake on AWS
- collect and normalize security logs from many sources
- run threat hunting queries over petabytes of logs
- write realtime detections as code in Python
- import Sigma rules for detection engineering
- replace a commercial SIEM with an open-source alternative
- transform and enrich logs during ingestion with VRL
- do DFIR investigations with Athena SQL queries

## When to choose
- you are an AWS-based security team wanting a self-hosted, vendor-neutral SIEM alternative
- you need petabyte-scale log storage with open table formats like Apache Iceberg
- you want detections managed as code with Sigma rule support
- you need realtime log normalization and enrichment without managing servers

## When to avoid
- you are not on AWS or need multi-cloud or on-premises deployment
- you want a turnkey managed SIEM with enterprise support out of the box
- your team cannot operate cloud infrastructure and IaC deployments
- you only need small-scale log analytics without security focus

## Facets
- artifact type: service
- maturity: active
- function: database, search-engine, alerting, etl, streaming, security, monitoring
- domain: security, big-data, cloud-computing, analytics
- platform: cloud, serverless, self-hosted, rust
- tags: security-data-lake, siem, threat-hunting, detection-as-code, apache-iceberg, log-management, dfir, secops, cloud-native, sigma-rules

## Member repositories
- matanolabs/matano (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:23.577607+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:37:59.670112+00:00, confidence not recorded.
  - readme: https://github.com/matanolabs/matano (fetched 2026-08-28T04:05:23.577607+00:00, sha f8d9f9c5081e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
