Tirreno

A security framework for detecting threats, fraud, and abuse through event ingestion and risk scoring.

Tirreno screenshot 1

Tirreno is an open-source, self-hosted web app and server that provides a security framework for threat detection, fraud prevention, and abuse monitoring. It focuses on detecting threats within application logic and compromised accounts that often bypass traditional firewalls, SIEMs, and WAFs. By monitoring activity inside the product, it identifies breaches that occur through account takeovers and logic abuse.

The software is deployed as a web application on a server and integrates with other products via SDKs and API calls. It allows administrators to ingest events with full context to monitor security incidents through a real-time dashboard. The system is designed for a straightforward installation process and can be deployed via Docker, Composer, or manual ZIP extraction on Unix-like systems.

Key features

  • Built-in dashboard for monitoring security events from a single interface
  • Rule engine for calculating risk scores via preset or custom rules
  • Single user view to analyze behavior patterns and activity timelines
  • Review queue to flag risky accounts for manual review or automatic suspension
  • Field audit trail to track modifications to important data fields
  • SDKs and API for event ingestion from external products
  • Preset rules for account takeover, credential stuffing, and bot detection
  • Monitoring for non-human identities including service accounts and API keys

Tirreno is built as a low-dependency PHP and PostgreSQL application, requiring PHP 8.0 to 8.3 and PostgreSQL 12 or greater. It is designed for a wide range of environments, including SaaS platforms, e-commerce marketplaces, and mission-critical applications, including those in air-gapped deployments. The architecture supports the detection of payment fraud, fake reviews, and promotional code exploitation in online stores, as well as the prevention of cross-tenant data leakage and privilege escalation in digital platforms. It also extends to industrial control systems to protect operational technology from unauthorized access.

This tool serves as an internal security layer for organizations needing detailed audit trails and fraud detection within their own infrastructure.

Last Modified
Software TypeWeb App / Server
Platform
Last Activity24 days ago
Repository Age1 year
LicenseAGPL-3.0
Open Source Alternative to
Open Source Software.io

Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.