# OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

Repository: https://github.com/OISF/suricata
Canonical: https://ross.abutalabs.com/products/suricata
Homepage: https://suricata.io
Language: C
License: GPL-2.0
License Family: copyleft
Topics: security, ids, ips, nsm, network-monitoring, suricata, intrusion-detection-system, intrusion-prevention-system, threat-hunting, cybersecurity, network-monitor
Last push: 2026-08-26T15:54:34+00:00

## Health v2 (maintenance only)
Score: 93/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 80, longevity 100
- inputs: {"age_days": 5132, "days_push": 7, "days_rel": 57, "gap_med": 49, "n_releases_24m": 18}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6571, forks 1760 (observed 2026-08-28T04:09:45.298511+00:00)

## What it is
Suricata is a high-performance network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM) engine written in C. It inspects live traffic or pcap files to detect threats, log events, and optionally block malicious traffic.

## Use cases
- detect intrusions on my network
- block malicious traffic inline with an ips
- monitor network traffic for threats
- analyze pcap files for suspicious activity
- threat hunting with network metadata and logs
- replace snort with a multithreaded ids
- generate network flow and protocol logs for security monitoring

## When to choose
- you need a mature, actively maintained IDS/IPS with deep protocol parsing and rule-based detection
- you want multithreaded performance for high-throughput network monitoring
- you need combined IDS, IPS, and NSM capabilities in one engine

## When to avoid
- you only need host-based intrusion detection or endpoint security
- you want a simple firewall rather than signature-based traffic inspection
- you need a lightweight sensor for embedded devices with minimal resources

## Facets
- artifact type: application
- maturity: stable
- function: security, monitoring, networking, alerting
- domain: security, networking, monitoring
- platform: cross-platform, cli
- tags: ids, ips, nsm, intrusion-detection, threat-hunting, deep-packet-inspection, network-security-monitoring, c, linux

## Member repositories
- OISF/suricata (main) score 93

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:45.298511+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:43:39.105253+00:00, confidence not recorded.
  - readme: https://github.com/OISF/suricata (fetched 2026-08-28T04:09:45.298511+00:00, sha 5eb6592791cb)
  - homepage: https://suricata.io (fetched 2026-08-29T08:40:09.631705+00:00, sha 44136fa355b3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
