SELKS is a free, open-source Suricata-based system for network intrusion detection and prevention, security monitoring and threat hunting. Its web interface manages Suricata rulesets and threat intelligence sources, as well as custom rules and IoC files. Predefined filters and contextual views support threat hunting, while thresholding and suppression can help reduce noisy alerts. SELKS 10 includes Suricata, Elasticsearch, Logstash, Kibana, Stamus Community Edition and functionality from Arkime, Evebox and CyberChef. It can capture packets connected to detection events and export session PCAP files for investigation or playback in SELKS or third-party tools. Deployment options include Docker Compose for Linux and Debian-based ISO images, with or without a desktop, for bare metal or virtual machines. SELKS is licensed under GPL 3.0-or-later. Stamus Networks describes it as suitable for many small-to-medium organizations and for people exploring Suricata, but says it was not designed for enterprise deployment. It is a legacy product: active enhancement stopped on January 1, 2025, and no future releases are planned.
Who it is for
SELKS may suit small-to-medium organizations and practitioners, researchers, educators, students or hobbyists exploring Suricata. It is not intended for enterprise deployment.
What is good
- Free under GPL 3.0-or-later
- Manages Suricata rulesets and threat intelligence sources
- Exports event-related session PCAP files
- Docker Compose and Debian ISO deployment options
What to know first
- No releases planned after January 1, 2025
- Not designed for enterprise deployment
Verdict
SELKS provides network detection, monitoring and hunting functions with several deployment options. Its legacy status and lack of planned future releases are important considerations before adopting it.
SELKS plans and pricing
All plansCompared on intrusion detection and prevention software
- Free plan
- Yes
- Deployment model
- software
- Network scope
- network
- Inline blocking
- Yes
- Encrypted traffic inspection
- Yes
- Threat intelligence
- Yes




