Free & Open Source

Enterprise Security with Distributed Threat Hunting

One node's detection โ†’ everyone's protection

Stop paying $50K+/year for cloud SIEMs that can't protect your edge. Deploy a complete SOC on a Raspberry Pi in 5 minutes. Free forever.

$0 Forever Free
<5min Deploy Time
50K+ Detection Rules
100% Self-Hosted
HookProbe 7-POD Mesh Architecture

Runs on hardware you already own

Raspberry Pi Banana Pi Radxa Waveshare NVIDIA Jetson Intel NUC Any ARM64 / x86_64

From $35 Raspberry Pi to enterprise servers - same protection, same simplicity

Deploy in One Command

No complex setup. No consultants. Just paste and go.

hookprobe@edge:~
$ git clone https://github.com/hookprobe/hookprobe.git
$ cd hookprobe && sudo ./install.sh

Works on Linux with Ubuntu, Open vSwitch, OpenFlow, and Podman installed

The Problem With Traditional SOCs

Enterprise security tools weren't built for the edge. Here's what you're dealing with:

๐Ÿ’ธ

Obscene Costs

Splunk, Elastic, CrowdStrike - they all want $50,000+/year. For most teams, that's the entire security budget.

HookProbe: $0 forever. AGPL licensed.
โ˜๏ธ

Cloud Lock-in

Your security data sits on someone else's servers. You pay per GB, per user, per everything.

HookProbe: 100% self-hosted. Your data, your hardware.
๐ŸŒ

Edge Blind Spots

Cloud SIEMs can't see what's happening at your branch offices, retail locations, or IoT networks.

HookProbe: Deploy at every edge. Full visibility.
๐ŸŽ“

Complexity Overload

Weeks of setup, consultants, training, certifications. Security shouldn't require a PhD.

HookProbe: 5-minute deploy. Works out of the box.

What You Get With HookProbe

Enterprise-grade security tools, pre-configured and ready to protect your network.

๐Ÿ”

NAPSE Engine

AI-native IDS/NSM/IPS with sub-millisecond alert latency, 50,000+ detection rules, and 10x less resource usage than legacy tools.

โšก

Sub-50ms Response

Automated threat containment with playbook-driven response. No waiting for cloud round-trips.

๐Ÿ“Š

Real-Time Dashboard

Beautiful XSOC dashboard with live threat feeds, network maps, and incident timelines.

๐ŸŽฏ

Qsecbit Score

Quantified security posture (0-100) updated in real-time. Know exactly where you stand.

The HTP-DSM-NEURO-QSECBIT-NSE Stack

Five integrated protocols form the backbone of distributed threat hunting. One node's detection becomes everyone's protection.

๐Ÿ”—

HTP

Transport Protocol

Keyless, post-quantum secure transport with NAT traversal. Adaptive streaming across UDP/TCP with anti-blocking fallback.

๐ŸŒ

DSM

Decentralized Mesh

Byzantine fault-tolerant consensus. 2/3 quorum validates threats. Microblocks with BLS signatures ensure integrity.

๐Ÿง 

NEURO

Neural Resonance

Living cryptography where neural weights become keys. Device identity through deterministic weight evolution.

๐Ÿ“Š

QSECBIT

Security Metric

Real-time resilience scoring (0-100%). L2-L7 detection across 27 attack types. GREEN/AMBER/RED status.

๐Ÿ”

NSE

Synaptic Encryption

Keys emerge from neural state - nobody knows the password. Ephemeral, bound to hardware, temporally unique.

Distributed Mesh Threat Hunting: All edge nodes (Sentinel, Guardian, Fortress, Nexus) form a mesh using HTP transport. When any node detects a threat, it creates a cryptographic microblock and broadcasts via DSM. After 2/3 consensus, all nodes block the threat instantly. Privacy preserved - only anonymized signatures shared, never raw data.

The 7-POD Architecture

Each POD is a specialized security container designed for edge deployment. Together, they form a complete autonomous SOC.

๐Ÿ”

NAPSE POD

AI-Native Packet Analysis with NAPSE Engine

Unified IDS/NSM/IPS with 16 protocol parsers, ML inference, and sub-millisecond alert latency.

๐Ÿ›ก๏ธ

AEGIS POD

Autonomous AI Defense Orchestration

8 specialized AI agents for cross-layer threat reasoning and autonomous response.

๐Ÿ“Š

Log Management POD

Centralized Security Event Logging

ClickHouse-powered log aggregation with real-time search and correlation.

๐ŸŽฏ

Threat Intelligence POD

Automated Threat Feed Integration

MISP and STIX/TAXII feeds for up-to-date IOC matching and threat enrichment.

๐Ÿ”“

Vulnerability POD

Continuous Vulnerability Assessment

Automated scanning with CVE correlation and risk prioritization.

โšก

Response POD

AI-Driven Incident Response Automation

Playbook-based automated response with human-in-the-loop escalation.

๐Ÿ–ฅ๏ธ

XSOC Dashboard

Unified Security Operations Center

Single-pane-of-glass visibility with Qsecbit scoring and real-time alerts.

Our Products

Five tiers of deployment - edge nodes form a distributed mesh, MSSP provides centralized management.

hookprobe@products ~ select-tier
$ hookprobe describe sentinel

HookProbe Sentinel Free Tier

The Watchful Eye - a lightweight validator service designed for getting started with HookProbe. Sentinel provides essential edge node validation and health monitoring, perfect for testing the platform or protecting a single device.

DEVICES 1 Device
RAM REQUIRED 256MB
HARDWARE COST ~$25
PRICE Free Forever
1 Device Limit Edge Validation Health Monitoring Mesh Connectivity 7-Day Retention
$ hookprobe describe guardian

HookProbe Guardian Personal Plan

The Perfect Mesh for Individuals. Create a protective mesh with up to 3 devices - one of each type. Perfect for small business owners like Mr. George's pizza bakery: a Fortress router for shop WiFi, a Guardian for travel protection, and a Sentinel watchdog.

DEVICES 3 Devices
CONSTRAINT 1 Per Type
RETENTION 30 Days
PRICE โ‚ฌ9/month
1 Sentinel + 1 Guardian + 1 Fortress L2-L7 Detection Real-time Threat Intel API Access Mesh Connected
$ hookprobe describe fortress

HookProbe Fortress Business Plan

Your Digital Stronghold - designed for growing businesses needing multi-site protection. Create up to 3 tenants with 9 devices shared across them. Perfect for businesses with multiple locations, franchises, or complex security requirements.

TENANTS Up to 3
DEVICES 9 Total
RETENTION 90 Days
PRICE โ‚ฌ29/month
Multi-Tenant Shared Device Pool Priority Support Webhooks Advanced Analytics GDPR Compliant
$ hookprobe describe nexus

HookProbe Nexus ML/AI Compute

The Regional Brain - an ML/AI compute hub for advanced threat detection, analytics, and intelligence processing. GPU-accelerated machine learning, long-term data retention, and federated learning coordination for security operations at scale. Currently in development.

DEPLOYMENT Server / Cloud
RAM REQUIRED 16GB+
GPU Recommended
STATUS In Development
GPU Acceleration ClickHouse Analytics Federated Learning Multi-Tenant Edge Orchestration Threat Intelligence
$ hookprobe describe mssp

HookProbe MSSP Central Brain

The Central Brain - a self-hosted management platform that aggregates all edge nodes into a single pane of glass. MSSP provides unified IAM, multi-tenant device management, and centralized security monitoring for the entire distributed mesh. Stand-alone, self-controlled.

DEPLOYMENT Self-Hosted
RAM REQUIRED 8GB+ (POC) / 16GB+ (Prod)
MANAGES Unlimited Edges
LICENSE Commercial
Single Pane of Glass HTP Protocol Multi-Tenant IAM Mesh Aggregation Qsecbit API n8n Automation

What is Qsecbit?

Qsecbit is HookProbe's proprietary quantum-resilient security metric. Unlike traditional security scores that rely on point-in-time assessments, Qsecbit provides continuous, real-time measurement of your infrastructure's true security posture.

Protection Status

๐ŸŸข > 55% GREEN All clear ยท Protected
๐ŸŸก 30-55% AMBER Monitoring ยท Stay alert
๐Ÿ”ด < 30% RED Under attack ยท Defending
87%
Qsecbit Score ๐ŸŸข Protected

Who Uses HookProbe?

From home labs to enterprise edge networks - HookProbe protects them all.

๐Ÿ 

Home Lab Enthusiasts

Protect your self-hosted services, NAS, and home network with enterprise-grade security on a Raspberry Pi.

Perfect for: Proxmox, TrueNAS, Home Assistant
๐Ÿข

Small Businesses

Get SOC-level protection without the SOC-level budget. Protect your office network, POS systems, and remote workers.

Perfect for: Retail, Clinics, Law Firms
๐Ÿ›ก๏ธ

MSPs & MSSPs

Deploy HookProbe at every client site for centralized monitoring. One dashboard, unlimited endpoints.

Perfect for: Multi-tenant security
๐Ÿ”ฌ

Security Researchers

Full packet capture, NAPSE detection logs, and AEGIS AI analysis for your honeypots, malware labs, and CTF environments.

Perfect for: Threat hunting, CTF, Research
๐Ÿญ

Industrial / OT Networks

Air-gapped, offline-capable IDS for manufacturing, utilities, and critical infrastructure.

Perfect for: SCADA, PLCs, ICS
๐Ÿซ

Education & Training

Teach cybersecurity with real tools. Students deploy, configure, and operate a full SOC stack.

Perfect for: Universities, Bootcamps

Frequently Asked Questions

Is HookProbe really free?

Yes, HookProbe is 100% free and open-source under the AGPL license. No subscription fees, no cloud costs, no per-user pricing. You own your data and infrastructure completely.

Why choose HookProbe over commercial SIEMs?

Commercial SIEMs typically cost $50,000+/year and require cloud connectivity. HookProbe is free, runs on low-cost hardware like Raspberry Pi, and operates at the edge without cloud dependency. Enterprise-grade detection, zero cost.

Can HookProbe run on Raspberry Pi?

Absolutely. HookProbe is optimized for Raspberry Pi 4/5, NVIDIA Jetson, and any ARM64/x86_64 device. A single Raspberry Pi 5 can monitor networks with 50+ devices.

How long does deployment take?

Under 5 minutes. Run our automated installer on any Linux device, and all 7 PODs are automatically configured and protecting your network. No consultants required.

Does HookProbe need cloud connectivity?

No. HookProbe is 100% self-hosted and works completely offline. All threat detection, log analysis, and incident response happens locally. Your data never leaves your network.

What security tools are included?

NAPSE for unified AI-native detection (50,000+ rules, sub-ms latency), AEGIS for autonomous AI defense, ClickHouse for log management, MISP for threat intel, plus automated response playbooks.

What is Qsecbit?

Qsecbit is HookProbe's real-time security score (0-100%) that measures your infrastructure's actual security posture. Score above 55% means GREEN (Protected), 30-55% is AMBER (Stay alert), below 30% is RED (Under attack). Updates continuously based on threat activity and defense effectiveness.

Who is HookProbe for?

Home lab enthusiasts, small businesses, MSPs, security researchers, and anyone who wants enterprise-grade security without enterprise costs. If you have devices on a network, HookProbe can protect them.

Stop Overpaying for Security

Your first Raspberry Pi SOC is 5 minutes away. No credit card. No sales calls. Just security.

Open source. Self-hosted. Free forever.

Docs Deploy Now