Suricata
Suricata is a free, open-source network IDS/IPS and Network Security Monitoring engine owned by the OISF nonprofit, used by enterprises, governments and commercial security vendors for high-performance threat detection.
- Company typePrivate
- Founded2010
- HeadquartersBoston, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
Suricata firmographics
Firmographics- Name
- Suricata
- Legal name
- Open Information Security Foundation
- Website
- https://suricata.io
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Suricata is a free, open-source network IDS/IPS and Network Security Monitoring engine owned by the OISF nonprofit, used by enterprises, governments and commercial security vendors for high-performance threat detection.
- Ownership category
- akta.pro rank
Suricata industry classification
Industry- Product category
- Network Intrusion Detection and Prevention
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Network Analytics & Observability (Flow/Packet/AI Ops for Networks) (HDAFAMAG)
Keywords
Where Suricata is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Suricata business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Consortium Membership: Organizations become consortium members to support development and gain non-GPL limited license for commercial use of Suricata. Members include Proofpoint, AWS, ANSSI, Juniper, Verizon, Corelight, and others.
- Training and Education: OISF provides instructor-led Suricata training courses including Network Security Monitoring, Intrusion Analysis and Threat Hunting, and Advanced Deployment. Proceeds after costs support Suricata development and OISF operations.
- Donations: Tax-deductible donations to OISF, a 501(c)(3) non-profit organization. Suricata is free and open source.
- DHS Funding: Initial funding for OISF came from the US Department of Homeland Security (DHS) to support development.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Suricata Open Source - Free download |
| Subscription | Multi-year contract | Instructor-led Training |
| Other | Multi-year contract | Custom/On-site Training |
Go-to-market motion1 record
Distribution channels6 records
Marketing channels9 records
Suricata product offering
Product offeringCore offering
Suricata is a free, open-source high-performance Network IDS, IPS, and Network Security Monitoring (NSM) engine that performs signature-based threat detection, automatic protocol detection, TLS/SSL and HTTP/DNS logging, file extraction from flows, full pcap capture, and Lua scripting for advanced detection logic. The engine is multi-threaded and capable of inspecting multi-gigabit traffic with native hardware acceleration support via PF_RING, AF_PACKET, and DPDK. Output is delivered through the industry-standard EVE JSON format for integration with Logstash, Splunk, Kibana, and other SIEM platforms. Suricata is distributed under GPLv2 with commercial non-GPL licensing available to OISF consortium members.
Product overview
Suricata is a free and open-source threat detection engine owned by the Open Information Security Foundation (OISF), a 501(c)(3) non-profit. The core Suricata Engine provides Network IDS, IPS, and Network Security Monitoring capabilities, with unified EVE JSON output for integration with analytics platforms. The product portfolio includes Suricata-Update for automated rule management, EveBox for graphical analysis, and Scirius CE for rule management and threat hunting. Version 8.0.0 was released July 2025 with significant protocol additions (DNS over HTTPS, LDAP, mDNS), detection improvements including transactional rules and entropy-based detection, and experimental firewall mode. Version 7.0.17 (July 2026) is the final release of the 7.x branch. The engine is written primarily in C with increasing Rust components (LibHTP, FTP, MIME, ENIP) and is available under GPLv2 with non-GPL licensing available through OISF for commercial use.
Differentiator
Problem solved
Functional benefit
Brands
- Suricata: Free and open source IDS/IPS engine managed by OISF
- SuriCon
- Suricata-Update
- Suricata Forum
Products and services
- Suricata Engine Free, open-source high-performance Network IDS, IPS, and Network Security Monitoring (NSM) engine. Provides signature-based threat detection, automatic protocol identification on any port, Lua scripting for advanced analysis, TLS/SSL and HTTP/DNS logging, file extraction from flows, full pcap capture support, and multi-gigabit traffic inspection with multi-threaded architecture. Hardware acceleration supported via PF_RING, AF_PACKET, and DPDK. Distributed under GPLv2 with non-GPL licensing available to OISF consortium members.
- Suricata-Update Official rule update tool for Suricata. Provides automatic rule updates, flowbit resolution, integration with the Emerging Threats Open ruleset, and Suricata Intel Index for discovering available rule sources.
- EveBox Graphical interface for Suricata EVE JSON output. Correlates alerts, anomaly events, and protocol data using Suricata's Flow ID for enhanced network security monitoring and incident analysis.
- Scirius CE Web-based Suricata rule and alert management platform for threat hunting and rule set administration.
Companies that use Suricata
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles2 records
Suricata technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration12 records
AI capability5 records
Feature11 records
Suricata partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered gold consortium member, consortium member and community partner.
- Eneagold consortium memberEnea, a global provider of telecom and cybersecurity software, has extended its Gold-level partnership with OISF. Enea contributes both funding and deep technical expertise to Suricata's development. Through this partnership, Enea developed the Qosmos Threat Detection SDK, combining Suricata's security capabilities with Enea's deep packet inspection traffic intelligence to enable cybersecurity vendors to embed world-class threat detection into their platforms.
- Proofpointconsortium memberProofpoint is a consortium member supporting OISF and Suricata development. Known for their ET Pro ruleset compatible with Suricata.
- AWS (Amazon Web Services)consortium memberAWS is a consortium member supporting OISF and Suricata development.
- Corelightconsortium memberCorelight is a consortium member supporting OISF and Suricata development. They offer Suricata-based network security solutions and have contributed to the ecosystem with Splunk apps and EveBox integrations.
- Juniper Networksconsortium memberJuniper Networks is a consortium member supporting OISF and Suricata development.
- ANSSIconsortium memberANSSI (Agence Nationale de la Sécurité des Systèmes d'Information) is France's national cybersecurity agency and consortium member supporting OISF.
- Verizonconsortium memberVerizon is a consortium member supporting OISF and Suricata development.
- Stamus Networkscommunity partnerStamus Networks, founded by Suricata developer Eric Leblond, offers commercial Suricata-based solutions and contributes to the community through tools like Scirius CE and EveBox integrations with Splunk.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Suricata competitors and assessment
Company assessmentDirect peers
- Stamus Networks: Commercial vendor founded by Suricata core developer Eric Leblond that builds products on top of Suricata (Scirius CE, Selks-derived solutions, Splunk integrations). Offers a commercial Suricata-based NDR alternative and is also an OISF Community Partner.
- Security Onion: Open-source Linux distribution for threat hunting, enterprise security monitoring, and log management that bundles Suricata as its core IDS/IPS engine. Direct downstream of Suricata with overlapping target users (SOC analysts, enterprise security teams).
- Zeek: Open-source network security monitoring framework (formerly Bro) focused on passive traffic analysis and rich protocol logging. Closely comparable to Suricata's NSM capabilities and a primary alternative for security teams choosing an open-source detection engine, often under a more permissive BSD license.
- Snort: Open-source IDS/IPS engine originally created by Martin Roesch and now maintained by Cisco Talos. The most direct open-source competitor to Suricata, sharing ruleset language concepts and target use cases (signature-based intrusion detection and prevention).
Emerging players
- Corelight: Commercial NDR platform built on Zeek (rather than Suricata), but competing in the same open-source-derived network detection market. OISF consortium member and ecosystem partner, illustrating the commercial NDR space Suricata-derived vendors also occupy.
- SELKS: Open-source Suricata-based network IDS/IPS distribution (now under Stamus Networks) providing a turnkey deployment of Suricata. Directly competes with Security Onion for self-hosted Suricata appliance deployments.
Others
- Wireshark: Open-source packet capture and protocol analyzer widely used by Suricata operators and security analysts. Not a direct competitor but a complementary tool often used alongside Suricata for packet-level forensics and NSM workflows.
Broad incumbents
- Palo Alto Networks: Enterprise NGFW and security platform leader with App-ID, Threat Prevention, and advanced threat detection capabilities. A broad incumbent competing for the same enterprise network security budget that Suricata-based deployments address.
- Cisco Secure Firewall (Talos): Commercial NGFW/IPS product line from Cisco that also owns and distributes Snort. A broad incumbent that bundles an open-source-style detection engine into a full enterprise security platform, competing for the same enterprise IPS/NGFW budget.
- AWS Network Firewall: Managed cloud-native network firewall service from AWS offering stateful inspection, IDS/IPS-style rule matching, and traffic filtering. Represents the cloud-provider-managed alternative to self-hosted Suricata deployments in AWS environments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Suricata social profiles
Digital presenceSuricata financial estimates
Financial estimateRevenue estimate
Valuation estimate
Suricata leadership team
Management profileNumber of profiles
Profiles13 records
Suricata funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Suricata M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Suricata
What does Suricata do?
Suricata is a free, open-source high-performance Network IDS, IPS, and Network Security Monitoring (NSM) engine that performs signature-based threat detection, automatic protocol detection, TLS/SSL and HTTP/DNS logging, file extraction from flows, full pcap capture, and Lua scripting for advanced detection logic. The engine is multi-threaded and capable of inspecting multi-gigabit traffic with native hardware acceleration support via PF_RING, AF_PACKET, and DPDK. Output is delivered through the industry-standard EVE JSON format for integration with Logstash, Splunk, Kibana, and other SIEM platforms. Suricata is distributed under GPLv2 with commercial non-GPL licensing available to OISF consortium members.
Is Suricata a public or private company?
Suricata is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Suricata founded?
Suricata was founded in 2010. It employs 1 to 10 people.
Where is Suricata based?
Suricata is headquartered in Boston, United States, in the North America region.
How does Suricata make money?
Four revenue lines are on record. Consortium Membership is the primary driver. The others are training and Education, donations and DHS Funding.
Who are Suricata's main competitors?
Direct peers on record are Stamus Networks, Security Onion, Zeek and Snort. Emerging players are Corelight and SELKS. Wireshark is listed as an others. Broad incumbents are Palo Alto Networks, Cisco Secure Firewall (Talos) and AWS Network Firewall.
Does Suricata have an API?
No public API is recorded for Suricata.
What industry is Suricata in?
Suricata's product category is Network Intrusion Detection and Prevention. Its primary akta.pro industry code is HDAFAMAG, Network Analytics & Observability (Flow/Packet/AI Ops for Networks). Its NAICS code is 5415 and its SIC code is 7372.