{"id":28604525,"url":"https://github.com/tirrenotechnologies/tirreno","last_synced_at":"2026-01-11T11:48:45.398Z","repository":{"id":267196208,"uuid":"900475823","full_name":"tirrenotechnologies/tirreno","owner":"tirrenotechnologies","description":"Monitor, analyze, and protect your web application from cyber fraud, account takeovers, fake accounts, bots, and abuse. Get started — free.","archived":false,"fork":false,"pushed_at":"2025-04-28T15:48:19.000Z","size":2717,"stargazers_count":523,"open_issues_count":3,"forks_count":62,"subscribers_count":10,"default_branch":"master","last_synced_at":"2025-05-30T07:15:21.571Z","etag":null,"topics":["analytics","antispam","application-monitoring","audit-trail","bot-detection","bot-management","ciso","fraud","fraud-detection","fraud-prevention","intelligence","intranet","log-analysis","monitoring","php-project","security","self-hosted","siem","web-analytics"],"latest_commit_sha":null,"homepage":"https://www.tirreno.com","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tirrenotechnologies.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":"AUTHORS.md","dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2024-12-08T21:24:42.000Z","updated_at":"2025-05-30T05:25:34.000Z","dependencies_parsed_at":null,"dependency_job_id":"73086897-5d01-432c-965c-44a99eb9fa5c","html_url":"https://github.com/tirrenotechnologies/tirreno","commit_stats":null,"previous_names":["tirrenotechnologies/tirreno"],"tags_count":6,"template":false,"template_full_name":null,"purl":"pkg:github/tirrenotechnologies/tirreno","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tirrenotechnologies%2Ftirreno","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tirrenotechnologies%2Ftirreno/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tirrenotechnologies%2Ftirreno/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tirrenotechnologies%2Ftirreno/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tirrenotechnologies","download_url":"https://codeload.github.com/tirrenotechnologies/tirreno/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tirrenotechnologies%2Ftirreno/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":259311485,"owners_count":22838726,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["analytics","antispam","application-monitoring","audit-trail","bot-detection","bot-management","ciso","fraud","fraud-detection","fraud-prevention","intelligence","intranet","log-analysis","monitoring","php-project","security","self-hosted","siem","web-analytics"],"created_at":"2025-06-11T18:00:58.237Z","updated_at":"2026-01-11T11:48:45.393Z","avatar_url":"https://github.com/tirrenotechnologies.png","language":"PHP","funding_links":[],"categories":["PHP","others"],"sub_categories":[],"readme":"# tirreno\n\n[![Codacy Badge](https://app.codacy.com/project/badge/Grade/ec30c28f67de476f8b98d2798079bdf0)](https://app.codacy.com/gh/TirrenoTechnologies/tirreno/dashboard?utm_source=gh\u0026utm_medium=referral\u0026utm_content=\u0026utm_campaign=Badge_grade)\n[![Docker Pulls](https://img.shields.io/docker/pulls/tirreno/tirreno?style=flat)](https://hub.docker.com/r/tirreno/tirreno/)\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://www.tirreno.com/\" target=\"_blank\"\u003e\n        \u003cimg src=\"https://www.tirreno.com/firstscreen.jpg\" alt=\"tirreno screenshot\" /\u003e\n    \u003c/a\u003e\n\u003c/p\u003e\n\ntirreno is open security analytics.\n\ntirreno *[tir.ˈrɛ.no]* helps understand, monitor, and protect your applications from cyber threats, account takeovers, bots, and abuse. While classic cybersecurity focuses on infrastructure and network perimeter, most breaches occur through compromised accounts and application logic abuse that bypasses firewalls, SIEM, WAFs, and other defenses.\n\ntirreno detects threats where they actually happen: inside your product. It adds a security layer to internal or external applications to identify malicious activity by analyzing user behavior, account activity, field changes history, and business logic abuse that infrastructure tools are unable to detect.\n\ntirreno is a few-dependency, \"low-tech\" PHP/PostgreSQL software application that can be downloaded and installed on your own web server. After a straightforward five-minute installation process, you can ingest events from your application through API calls and immediately access a real-time threat dashboard.\n\n## Application types\n\n* **Self-hosted, internal and legacy apps**: Embed security layer\n  to extend your security through audit trails, protect user accounts\n  from takeover, detect cyber threats and monitor insider threats.\n* **SaaS and digital platforms**: Prevent cross-tenant data leakage,\n  online fraud, privilege escalation, data exfiltration and business\n  logic abuse.\n* **Mission critical applications**: Sensitive application protection,\n  even in air-gapped deployments.\n* **Industrial control systems (ICS) and command \u0026 control (C2)**: Protect,\n  operational technology, command systems, and critical infrastructure\n  platforms from unauthorized access and malicious commands.\n* **Non-human identities (NHIs)**: Monitor service accounts, API keys,\n  bot behaviors, and detect compromised machine identities.\n* **API-first applications**: Protect against abuse, rate limiting\n  bypasses, scraping, and unauthorized access.\n\n## Industries\n\n* **Government and public sector**: Protect citizen data, detect insider\n  threats, ensure compliance, and maintain data sovereignty.\n* **Banking and fintech**: Real-time transaction monitoring, anomalous\n  login detection, synthetic identity fraud protection, regulator\n  compliance.\n* **Energy and utilities**: Protect critical infrastructure, detect\n  unauthorized access to control systems, monitor insider threats,\n  and ensure compliance with energy sector regulations.\n* **Healthcare portals**: Protect patient data, monitor unauthorized\n  PHI/PII access, detect staff behaivour anomalies, ensure HIPAA compliance.\n* **Educational platforms**: Protect student data, detect account sharing\n  and cheating, ensure FERPA compliance.\n* **E-commerce and retail**: Detect payment fraud, bot attacks, credential\n  stuffing, and protect customer accounts.\n* **IoT and connected devices**: Monitor authentication, detect compromised\n  devices, prevent unauthorized access.\n* **Gaming platforms**: Detect account takeover, cheating, bot activity,\n  and protect in-game economies.\n\n## Live demo\n\nCheck out the live demo at [play.tirreno.com](https://play.tirreno.com) (*admin/tirreno*).\n\n## Requirements\n\n* **PHP**: Version 8.0 to 8.3\n* **PostgreSQL**: Version 12 or greater\n* **PHP extensions**: `PDO_PGSQL`, `cURL`\n* **HTTP web server**: `Apache` with `mod_rewrite` and `mod_headers` enabled\n* **Operating system**: A Unix-like system is recommended\n* **Minimum hardware requirements**:\n  * **PostgreSQL**: 512 MB RAM (4 GB recommended)\n  * **Application**: 128 MB RAM (1 GB recommended)\n  * **Storage**: Approximately 3 GB PostgreSQL storage per 1 million events\n\n## Docker-based installation (optional)\n\nTo run tirreno within docker container you may use image published on [dockerhub](https://hub.docker.com/r/tirreno/tirreno).\n\n```bash\ndocker pull tirreno/tirreno:latest\n```\n\n## Quickstart install\n\n1. [Download](https://www.tirreno.com/download.php) the latest version of tirreno (ZIP file).\n2. Extract the tirreno-master.zip file to the location where you want it installed on your web server.\n3. Navigate to `http://your-domain.example/install/index.php` in a browser to launch the installation process.\n4. After the successful installation, delete the `install/` directory and its contents.\n5. Navigate to `http://your-domain.example/signup/` in a browser to create administrator account.\n6. For cron jobs setup insert the following schedule (every 10 minutes) expression with `crontab -e` command or by editing `/var/spool/cron/your-web-server` file:\n\n```\n*/10 * * * * /usr/bin/php /absolute/path/to/tirreno/index.php /cron\n```\n\n## Using Heroku (optional)\n\nClick [here](https://heroku.com/deploy?template=https://github.com/tirrenotechnologies/tirreno) to launch heroku deployment.\n\n## Documentation\n\nSee the [User Guide](https://docs.tirreno.com/) for details on how to use tirreno.\n\n## About\n\nThe tirreno project started as a proprietary system in 2021 and was open-sourced (AGPL) in December 2024.\n\nBehind tirreno is a blend of extraordinary engineers and professionals, with over a decade of experience in cyberdefence. We solve real people's challenges through love in *ascétique* code and open technologies. tirreno is not VC-motivated. Our inspiration comes from the daily threats posed by organized cybercriminals, driving us to reimagine\nthe place of security in modern applications.\n\n## Why the name tirreno?\n\nTyrrhenian people may have lived in Tuscany and eastern Switzerland as far back as 800 BC. The term \"Tyrrhenian\" became more commonly associated with the Etruscans, and it is from them that the Tyrrhenian Sea derives its name, which is still in use today.\n\nAccording to historical sources, Tyrrhenian people were the first to use trumpets for signaling about coming threats, which was later adopted by Greek and Roman military forces.\n\nWhile working on the logo, we conducted our own historical study and traced mentions of 'tirreno' back to the 15th-century printed edition of the Vulgate (the Latin Bible). We kept it lowercase to stay true to the original — quite literally, by the book. The tirreno wordmark stands behind the horizon line, as a metaphor of the endless evolutionary cycle of the threat landscape and our commitment to rise over it.\n\n## Links\n\n* [Website](https://www.tirreno.com)\n* [Live demo](https://play.tirreno.com)\n* [Documentation](https://docs.tirreno.com)\n* [Mattermost community](https://chat.tirreno.com)\n\n## Reporting a security issue\n\nIf you've found a security-related issue with tirreno, please email security@tirreno.com. Submitting the issue on GitHub exposes the vulnerability to the public, making it easy to exploit. We will publicly disclose the security issue after it has been resolved.\n\nAfter receiving a report, tirreno will take the following steps:\n\n* Confirm that the report has been received and is being addressed.\n* Attempt to reproduce the problem and confirm the vulnerability.\n* Release new versions of all the affected packages.\n* Announce the problem prominently in the release notes.\n* If requested, give credit to the reporter.\n\n## License\n\nThis program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License (AGPL) as published by the Free Software Foundation version 3.\n\nThe name \"tirreno\" is a registered trademark of tirreno technologies sàrl, and tirreno technologies sàrl hereby declines to grant a trademark license to \"tirreno\" pursuant to the GNU Affero General Public License version 3 Section 7(e), without a separate agreement with tirreno technologies sàrl.\n\nThis program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See GNU Affero General Public License for more details.\n\nYou should have received a copy of the GNU Affero General Public License along with this program. If not, see [GNU Affero General Public License v3](https://www.gnu.org/licenses/agpl-3.0.txt).\n\n## Authors\n\ntirreno Copyright (C) 2025 tirreno technologies sàrl, Vaud, Switzerland. (License AGPLv3)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftirrenotechnologies%2Ftirreno","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftirrenotechnologies%2Ftirreno","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftirrenotechnologies%2Ftirreno/lists"}