yzhao062/pyod
PyOD is a comprehensive Python library for multi-modal anomaly detection, offering 60+ detectors and an agentic workflow for AI agents to drive investigations across various data types.
Awesome AI for Infra › Anomaly Detection
RITA (Real Intelligence Threat Analytics) is a robust open-source framework designed for the specialized task of detecting sophisticated command and control (C2) communication within network traffic. By ingesting Zeek logs in TSV or JSON format, RITA applies several analytical capabilities to uncover malicious activity. Key features include active beaconing detection, which identifies regular, rhythmic communication patterns often indicative of C2 channels; long connection detection, pinpointing unusually extended network sessions; and DNS tunneling detection, which uncovers covert communication methods exploiting DNS queries. Furthermore, RITA integrates with threat intelligence feeds to cross-reference suspicious domains and hosts, enhancing its ability to identify known malicious entities. The framework is deployed via Docker and offers a command-line interface for importing data, configuring settings, and searching for threats with a GitHub-style syntax. While not explicitly using 'AI' or 'ML' terminology in its description, its core function of detecting subtle, often complex, network anomalies and patterns for C2 communication aligns with an AI-for-Ops approach, particularly in the realm of threat intelligence and behavioral analysis for SecOps, as it automates the detection of patterns that human analysts would struggle to find at scale.
https://github.com/activecm/rita
PyOD is a comprehensive Python library for multi-modal anomaly detection, offering 60+ detectors and an agentic workflow for AI agents to drive investigations across various data types.
TODS is a comprehensive automated machine learning system for multivariate time-series outlier detection, providing modules for preprocessing, feature extraction, and a wide array of detection algo...
Orion is an open-source machine learning library from MIT's Data to AI Lab, focused on unsupervised time series anomaly detection using various AI-driven pipelines.
Telemanom is a framework using LSTMs and automatic thresholding for unsupervised anomaly detection in multivariate time series data, originally developed for spacecraft telemetry.
datastream.io is an open-source framework for real-time anomaly detection in streaming data using Python, Elasticsearch, and Kibana.
Luminaire is a Python package from Zillow that provides ML-driven solutions for monitoring time series data through automated anomaly detection and forecasting.
MIDAS is a C++ implementation for real-time anomaly detection in dynamic, time-evolving graphs, designed to identify intrusions, fraud, and fake rating anomalies with high accuracy and speed.
Skyline is a real-time anomaly detection and time series analysis system designed for passive monitoring of numerous high-resolution metrics without pre-configured models or thresholds.