Awesome AI for Infra › Anomaly Detection

GACWR/OpenUBA

⭐ 520 Python added to this list on 2026-07-20 repository created 2019-09-24

OpenUBA is an open-source User and Entity Behavior Analytics (UEBA) framework crafted for security analytics. Unlike many UBA platforms that use opaque 'black box' data science, OpenUBA champions an 'open-model' approach, providing transparency into the underlying models and their operations. This transparency is crucial for security analysts who need to understand how anomalies, baselines, and security cases are generated, aiding in compliance, investigation, and decision-making processes. The platform integrates a community-driven marketplace for security models, allowing users to install, share, or even commercialize models for various use cases. Its architecture is Kubernetes-native, built for modularity and cloud-nativity, with all components containerized. It uses a lightweight infrastructure, designed for scalability without heavy pipeline orchestrators. The tech stack includes Next.js for the frontend, FastAPI for the backend API, PostGraphile for GraphQL, and a custom Kubernetes operator for orchestrating ephemeral jobs for model training and inference. Data processing leverages PostgreSQL, Elasticsearch, and Apache Spark, supporting frameworks like scikit-learn, PyTorch, and TensorFlow for diverse security analytics tasks.

https://github.com/GACWR/OpenUBA

UEBAsecurity analyticsopen-modelanomaly detectionthreat huntingcybersecuritymachine learningKubernetesSIEMsecurity monitoringbehavioral analysis

Also in Anomaly Detection

yzhao062/pyod

PyOD is a comprehensive Python library for multi-modal anomaly detection, offering 60+ detectors and an agentic workflow for AI agents to drive investigations across various data types.

datamllab/tods

TODS is a comprehensive automated machine learning system for multivariate time-series outlier detection, providing modules for preprocessing, feature extraction, and a wide array of detection algo...

sintel-dev/Orion

Orion is an open-source machine learning library from MIT's Data to AI Lab, focused on unsupervised time series anomaly detection using various AI-driven pipelines.

khundman/telemanom

Telemanom is a framework using LSTMs and automatic thresholding for unsupervised anomaly detection in multivariate time series data, originally developed for spacecraft telemetry.

MentatInnovations/datastream.io

datastream.io is an open-source framework for real-time anomaly detection in streaming data using Python, Elasticsearch, and Kibana.

zillow/luminaire

Luminaire is a Python package from Zillow that provides ML-driven solutions for monitoring time series data through automated anomaly detection and forecasting.

Stream-AD/MIDAS

MIDAS is a C++ implementation for real-time anomaly detection in dynamic, time-evolving graphs, designed to identify intrusions, fraud, and fake rating anomalies with high accuracy and speed.

activecm/rita

RITA (Real Intelligence Threat Analytics) is an open-source framework that detects command and control (C2) communication by analyzing network traffic, identifying beaconing, long connections, DNS ...