SimWitty is an open source Sim. Written in C# for .Net Framework and available under the BSD license, SimWitty is a modular platform for monitoring networks.
A Security Information Management (Sim) system is a tool for identifying and alerting on abnormal events. A Sim collects information about an environment’s state and flow. That is, it correlates computers’ event logs with network traffic in a single database. The data is then analyzed, correlated, and reported on. The benefit to the InfoSec professional is in identifying unusual and potentially malicious behavior, while keeping an entire trail for further investigation.