Free & Open Source

Enterprise Security with Distributed Threat Hunting

One node's detection → everyone's protection

Stop paying $50K+/year for cloud SIEMs that can't protect your edge. Deploy a complete SOC on a Raspberry Pi in 5 minutes. Free forever.

$0 Forever Free
<5min Deploy Time
50K+ Detection Rules
100% Self-Hosted
HookProbe 7-POD Mesh Architecture

Runs on hardware you already own

Raspberry Pi Banana Pi Radxa Waveshare NVIDIA Jetson Intel NUC Any ARM64 / x86_64

From $35 Raspberry Pi to enterprise servers - same protection, same simplicity

Deploy in One Command

No complex setup. No consultants. Just paste and go.

hookprobe@edge:~
$ git clone https://github.com/hookprobe/hookprobe.git
$ cd hookprobe && sudo ./install.sh

Works on Linux with Ubuntu, Open vSwitch, OpenFlow, and Podman installed

The Problem With Traditional SOCs

Enterprise security tools weren't built for the edge. Here's what you're dealing with:

💸

Obscene Costs

Splunk, Elastic, CrowdStrike - they all want $50,000+/year. For most teams, that's the entire security budget.

HookProbe: $0 forever. AGPL licensed.
☁️

Cloud Lock-in

Your security data sits on someone else's servers. You pay per GB, per user, per everything.

HookProbe: 100% self-hosted. Your data, your hardware.
🐌

Edge Blind Spots

Cloud SIEMs can't see what's happening at your branch offices, retail locations, or IoT networks.

HookProbe: Deploy at every edge. Full visibility.
🎓

Complexity Overload

Weeks of setup, consultants, training, certifications. Security shouldn't require a PhD.

HookProbe: 5-minute deploy. Works out of the box.

What You Get With HookProbe

Enterprise-grade security tools, pre-configured and ready to protect your network.

🔍

NAPSE Engine

AI-native IDS/NSM/IPS with sub-millisecond alert latency, 50,000+ detection rules, and 10x less resource usage than legacy tools.

Sub-50ms Response

Automated threat containment with playbook-driven response. No waiting for cloud round-trips.

📊

Real-Time Dashboard

Beautiful XSOC dashboard with live threat feeds, network maps, and incident timelines.

🎯

Qsecbit Score

Quantified security posture (0-100) updated in real-time. Know exactly where you stand.

The HTP-DSM-NEURO-QSECBIT-NSE Stack

Five integrated protocols form the backbone of distributed threat hunting. One node's detection becomes everyone's protection.

🔗

HTP

Transport Protocol

Keyless, post-quantum secure transport with NAT traversal. Adaptive streaming across UDP/TCP with anti-blocking fallback.

🌐

DSM

Decentralized Mesh

Byzantine fault-tolerant consensus. 2/3 quorum validates threats. Microblocks with BLS signatures ensure integrity.

🧠

NEURO

Neural Resonance

Living cryptography where neural weights become keys. Device identity through deterministic weight evolution.

📊

QSECBIT

Security Metric

Real-time resilience scoring (0-100%). L2-L7 detection across 27 attack types. GREEN/AMBER/RED status.

🔐

NSE

Synaptic Encryption

Keys emerge from neural state - nobody knows the password. Ephemeral, bound to hardware, temporally unique.

Distributed Mesh Threat Hunting: All edge nodes (Sentinel, Guardian, Fortress, Nexus) form a mesh using HTP transport. When any node detects a threat, it creates a cryptographic microblock and broadcasts via DSM. After 2/3 consensus, all nodes block the threat instantly. Privacy preserved - only anonymized signatures shared, never raw data.

The 7-POD Architecture

Each POD is a specialized security container designed for edge deployment. Together, they form a complete autonomous SOC.

🔍

NAPSE POD

AI-Native Packet Analysis with NAPSE Engine

Unified IDS/NSM/IPS with 16 protocol parsers, ML inference, and sub-millisecond alert latency.

🛡️

AEGIS POD

Autonomous AI Defense Orchestration

8 specialized AI agents for cross-layer threat reasoning and autonomous response.

📊

Log Management POD

Centralized Security Event Logging

ClickHouse-powered log aggregation with real-time search and correlation.

🎯

Threat Intelligence POD

Automated Threat Feed Integration

MISP and STIX/TAXII feeds for up-to-date IOC matching and threat enrichment.

🔓

Vulnerability POD

Continuous Vulnerability Assessment

Automated scanning with CVE correlation and risk prioritization.

Response POD

AI-Driven Incident Response Automation

Playbook-based automated response with human-in-the-loop escalation.

🖥️

XSOC Dashboard

Unified Security Operations Center

Single-pane-of-glass visibility with Qsecbit scoring and real-time alerts.

Our Products

Five tiers of deployment - edge nodes form a distributed mesh, MSSP provides centralized management.

hookprobe@products ~ select-tier
$ hookprobe describe sentinel

HookProbe Sentinel Free Tier

The Watchful Eye - a lightweight validator service designed for getting started with HookProbe. Sentinel provides essential edge node validation and health monitoring, perfect for testing the platform or protecting a single device.

DEVICES 1 Device
RAM REQUIRED 256MB
HARDWARE COST ~$25
PRICE Free Forever
1 Device Limit Edge Validation Health Monitoring Mesh Connectivity 7-Day Retention
$ hookprobe describe guardian

HookProbe Guardian Personal Plan

The Perfect Mesh for Individuals. Create a protective mesh with up to 3 devices - one of each type. Perfect for small business owners like Mr. George's pizza bakery: a Fortress router for shop WiFi, a Guardian for travel protection, and a Sentinel watchdog.

DEVICES 3 Devices
CONSTRAINT 1 Per Type
RETENTION 30 Days
PRICE €9/month
1 Sentinel + 1 Guardian + 1 Fortress L2-L7 Detection Real-time Threat Intel API Access Mesh Connected
$ hookprobe describe fortress

HookProbe Fortress Business Plan

Your Digital Stronghold - designed for growing businesses needing multi-site protection. Create up to 3 tenants with 9 devices shared across them. Perfect for businesses with multiple locations, franchises, or complex security requirements.

TENANTS Up to 3
DEVICES 9 Total
RETENTION 90 Days
PRICE €29/month
Multi-Tenant Shared Device Pool Priority Support Webhooks Advanced Analytics GDPR Compliant
$ hookprobe describe nexus

HookProbe Nexus ML/AI Compute

The Regional Brain - an ML/AI compute hub for advanced threat detection, analytics, and intelligence processing. GPU-accelerated machine learning, long-term data retention, and federated learning coordination for security operations at scale. Currently in development.

DEPLOYMENT Server / Cloud
RAM REQUIRED 16GB+
GPU Recommended
STATUS In Development
GPU Acceleration ClickHouse Analytics Federated Learning Multi-Tenant Edge Orchestration Threat Intelligence
$ hookprobe describe mssp

HookProbe MSSP Central Brain

The Central Brain - a self-hosted management platform that aggregates all edge nodes into a single pane of glass. MSSP provides unified IAM, multi-tenant device management, and centralized security monitoring for the entire distributed mesh. Stand-alone, self-controlled.

DEPLOYMENT Self-Hosted
RAM REQUIRED 8GB+ (POC) / 16GB+ (Prod)
MANAGES Unlimited Edges
LICENSE Commercial
Single Pane of Glass HTP Protocol Multi-Tenant IAM Mesh Aggregation Qsecbit API n8n Automation

What is Qsecbit?

Qsecbit is HookProbe's proprietary quantum-resilient security metric. Unlike traditional security scores that rely on point-in-time assessments, Qsecbit provides continuous, real-time measurement of your infrastructure's true security posture.

Protection Status

🟢 > 55% GREEN All clear · Protected
🟡 30-55% AMBER Monitoring · Stay alert
🔴 < 30% RED Under attack · Defending
87%
Qsecbit Score 🟢 Protected

Who Uses HookProbe?

From home labs to enterprise edge networks - HookProbe protects them all.

🏠

Home Lab Enthusiasts

Protect your self-hosted services, NAS, and home network with enterprise-grade security on a Raspberry Pi.

Perfect for: Proxmox, TrueNAS, Home Assistant
🏢

Small Businesses

Get SOC-level protection without the SOC-level budget. Protect your office network, POS systems, and remote workers.

Perfect for: Retail, Clinics, Law Firms
🛡️

MSPs & MSSPs

Deploy HookProbe at every client site for centralized monitoring. One dashboard, unlimited endpoints.

Perfect for: Multi-tenant security
🔬

Security Researchers

Full packet capture, NAPSE detection logs, and AEGIS AI analysis for your honeypots, malware labs, and CTF environments.

Perfect for: Threat hunting, CTF, Research
🏭

Industrial / OT Networks

Air-gapped, offline-capable IDS for manufacturing, utilities, and critical infrastructure.

Perfect for: SCADA, PLCs, ICS
🏫

Education & Training

Teach cybersecurity with real tools. Students deploy, configure, and operate a full SOC stack.

Perfect for: Universities, Bootcamps

Frequently Asked Questions

Is HookProbe really free?

Yes, HookProbe is 100% free and open-source under the AGPL license. No subscription fees, no cloud costs, no per-user pricing. You own your data and infrastructure completely.

Why choose HookProbe over commercial SIEMs?

Commercial SIEMs typically cost $50,000+/year and require cloud connectivity. HookProbe is free, runs on low-cost hardware like Raspberry Pi, and operates at the edge without cloud dependency. Enterprise-grade detection, zero cost.

Can HookProbe run on Raspberry Pi?

Absolutely. HookProbe is optimized for Raspberry Pi 4/5, NVIDIA Jetson, and any ARM64/x86_64 device. A single Raspberry Pi 5 can monitor networks with 50+ devices.

How long does deployment take?

Under 5 minutes. Run our automated installer on any Linux device, and all 7 PODs are automatically configured and protecting your network. No consultants required.

Does HookProbe need cloud connectivity?

No. HookProbe is 100% self-hosted and works completely offline. All threat detection, log analysis, and incident response happens locally. Your data never leaves your network.

What security tools are included?

NAPSE for unified AI-native detection (50,000+ rules, sub-ms latency), AEGIS for autonomous AI defense, ClickHouse for log management, MISP for threat intel, plus automated response playbooks.

What is Qsecbit?

Qsecbit is HookProbe's real-time security score (0-100%) that measures your infrastructure's actual security posture. Score above 55% means GREEN (Protected), 30-55% is AMBER (Stay alert), below 30% is RED (Under attack). Updates continuously based on threat activity and defense effectiveness.

Who is HookProbe for?

Home lab enthusiasts, small businesses, MSPs, security researchers, and anyone who wants enterprise-grade security without enterprise costs. If you have devices on a network, HookProbe can protect them.

Stop Overpaying for Security

Your first Raspberry Pi SOC is 5 minutes away. No credit card. No sales calls. Just security.

Open source. Self-hosted. Free forever.

Docs Deploy Now