Stars
Forks
Watchers
Developer links
Wazuh
Protecting over 10,000 organizations worldwide with 16,000+ GitHub stars, Wazuh delivers enterprise-grade security operations through a fully open-source platform with zero feature gating. The unified XDR and SIEM solution deploys lightweight agents across Linux, Windows, macOS, Solaris, AIX, and HP-UX endpoints that stream security telemetry to a centralized cluster built on OpenSearch for indexing and the Wazuh Dashboard for visualization and management. Core capabilities include real-time file integrity monitoring with inotify-based detection and who-data attribution, automated vulnerability assessment that correlates software inventories against continuously updated CVE databases, Security Configuration Assessment against CIS benchmarks, rootkit detection, and log data analysis with a rules engine supporting over 3,000 built-in detection rules mapped to MITRE ATT&CK tactics and techniques. Wazuh monitors cloud infrastructure at the API level with native modules for AWS, Azure, and Google Cloud, detects container anomalies through Docker engine integration, and ingests third-party telemetry via syslog and REST APIs from sources like VirusTotal, TheHive, YARA, Suricata, and PagerDuty. Pre-built compliance dashboards and reports cover PCI DSS, HIPAA, NIST 800-53, GDPR, and TSC frameworks. Active response capabilities automatically trigger countermeasures including firewall rule updates, account lockouts, and endpoint isolation when threats are detected. The platform scales horizontally with multi-node clustering for high availability. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. GPL-2.0 licensed.
Benefits
- Unified XDR and SIEM Platform
- Consolidates endpoint detection, log analysis, vulnerability assessment, and compliance reporting into a single platform, eliminating the need for multiple disconnected security tools and reducing operational complexity.
- Zero-Cost Enterprise Security Features
- All capabilities including RBAC, threat hunting, AI-assisted detection, compliance mapping, and file integrity monitoring are included in the GPL-2.0 binary with no feature gating or per-agent licensing fees.
- Multi-Cloud Infrastructure Monitoring
- Native API-level modules for AWS, Azure, and Google Cloud detect misconfigurations and security events across cloud workloads, containers, and Kubernetes clusters with automated posture management.
- Regulatory Compliance Automation
- Pre-built dashboards and automated reports for PCI DSS, HIPAA, NIST 800-53, GDPR, and TSC frameworks streamline audit preparation and provide continuous compliance monitoring with evidence collection.
Features
- File Integrity Monitoring
- Real-time detection of file changes using inotify on Linux and SACL auditing on Windows with cryptographic checksum verification and who-data attribution for forensic analysis.
- Vulnerability Detection
- Automated software inventory collection correlated against CVE databases to identify and prioritize known vulnerabilities across all monitored endpoints and cloud instances.
- Threat Intelligence Integration
- Ingests feeds from VirusTotal, YARA rules, Suricata IDS, MITRE ATT&CK mapping, and custom threat intelligence sources via syslog and REST API connectors.
- Active Response Engine
- Automatically triggers countermeasures including iptables firewall updates, account lockouts, and process termination when detection rules match identified threats.
- Security Configuration Assessment
- Scans endpoint configurations against CIS benchmarks and custom policies to detect misconfigurations, weak permissions, and non-compliant settings across the infrastructure.