sigwood is an open-source CLI tool designed for security analysts to hunt for command-and-control beacons, DNS anomalies, and cloud-account irregularities directly in log files. It works without the need for a SIEM or agents and supports various log sources such as Zeek, syslog, Pi-hole, dnsmasq, and AWS CloudTrail. The tool is MIT licensed and suitable for blue teams and threat hunters.
sigwood is a Security & compliance platforms product. It focuses on detecting command-and-control beacons, DNS anomalies, and suspicious cloud account activity in log files without requiring a SIEM or agents. sigwood is an open-source project aimed at security analysts. The project is open source (MIT). sigwood is available on the command line.
Behind sigwood is helixmap, and the product first shipped in 2026. The project is developed in the open on GitHub with 64 stars and 42 commits in the last 90 days. Among its 11 catalogued features are C2 beacon detection, DNS anomaly detection, and cloud account monitoring.
Latest indexed changes and source events
Other apps tracked under the same category.