Open source · MIT licensed

Your security operations platform, self-hosted and open.

Threat monitoring, analysis, and automated response — with full control over your data. From git clone to running scans with Docker Compose.

11

Integrated services

52

Security tools

MIT

Open source

Up and running with Docker Compose

Clone the repository, generate the secrets, name the first administrator, and start the stack.

Terminal
$ git clone https://github.com/fabriziosalmi/wildbox.git
$ cd wildbox
$ make generate-secrets
# edit .env: set INITIAL_ADMIN_EMAIL, the first administrator's login
$ make validate-secrets
$ docker compose up -d --wait
# open https://localhost and sign in as INITIAL_ADMIN_EMAIL with the INITIAL_ADMIN_PASSWORD from .env

No default credentials

make generate-secrets writes a random value for every secret, the first administrator's password included, into .env; make validate-secrets refuses any placeholder left.

Container-native

Independent microservices orchestrated with Docker Compose. Optional profiles add workflow automation, Prometheus and scheduled backups.

Operational basics

Health checks, restart policies, and persistent volumes are configured in the Compose files out of the box.

One platform for security operations

Modular services that work together — use what you need, ignore the rest.

Threat intelligence

Collect indicators from 7 public feeds (abuse.ch, PhishTank, AbuseIPDB and others) on a schedule, and look them up in one place.

Cloud security (CSPM)

Run 22 configuration checks against live AWS accounts and keep each scan's report. AWS only: scans of other providers are refused.

Vulnerability management

Record, prioritize, and track vulnerabilities (CVEs) across your assets through to remediation, with SLA checks and alert rules.

Automated response (SOAR)

Orchestrate incident response with YAML-based playbooks for repeatable, automated workflows.

LLM analysis

Threat-enrichment reports for indicators, generated with Anthropic Claude once you set an Anthropic API key. The rest of the platform works without it.

Identity & access

Users, teams, and role-based access control (RBAC) behind a single authenticated API gateway.

How it works

1

Deploy the stack

Bring up the services with Docker Compose. Each component is an independent microservice behind the API gateway.

2

Connect your infrastructure

Add your assets to the inventory and your AWS accounts to the cloud scans. The sensor collects host telemetry with osquery and sends it through the gateway, with an API key of a team member, to the data service, which keeps it per team.

3

Scan and monitor

Run the security tools and the AWS posture checks, and let the data service collect threat intelligence feeds on a schedule.

4

Respond and report

Trigger YAML playbooks for automated response, and ask the agents service for an analysis of a suspicious indicator.

5

Extend it

It's open source under the MIT license — modify, extend, and integrate freely. No vendor lock-in.

Who it's for

Organizations

Run security operations on your own infrastructure, keeping full data sovereignty and avoiding vendor lock-in.

Security teams

A modular, extensible platform to customize and integrate with your existing tools and workflows.

DevOps & platform teams

Security visibility for self-hosted infrastructure, without depending on proprietary cloud security tooling.

Researchers

Build threat intelligence pipelines and prototype detection ideas against real security data.

Own your security operations

Clone the repository and have the platform running on your own infrastructure.