Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Security
  3. wazuh

wazuh

NOASSERTIONC++v4.14.7

An open-source unified XDR and SIEM platform for threat prevention, detection, and response across endpoints and cloud workloads.

Visit WebsiteGitHubGitHub
16.8k stars2.5k forks0 contributors

What is wazuh?

Wazuh is an open-source unified XDR and SIEM platform designed for threat prevention, detection, and response. It protects endpoints and cloud workloads by integrating agent-based monitoring with a central management server, providing capabilities like intrusion detection, log analysis, and vulnerability assessment. The platform helps organizations secure diverse environments, from on-premises systems to containerized and cloud-based infrastructure.

Target Audience

Security teams, DevOps engineers, and IT administrators responsible for securing hybrid or multi-cloud environments, ensuring regulatory compliance, and managing threat detection across endpoints and workloads.

Value Proposition

Developers choose Wazuh for its comprehensive, open-source approach to security that unifies XDR and SIEM functionalities without licensing costs. Its scalability, multi-platform support, and deep integrations with tools like Elastic Stack and cloud providers offer a flexible alternative to proprietary solutions.

Overview

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Use Cases

Best For

  • Unified threat detection across on-premises and cloud environments
  • Meeting PCI DSS, GDPR, or GPG13 regulatory compliance requirements
  • Monitoring Docker containers and Kubernetes clusters for security threats
  • Automated vulnerability assessment and configuration compliance checks
  • Real-time log analysis and intrusion detection for hybrid infrastructure
  • File integrity monitoring to detect unauthorized changes or compromises

Not Ideal For

  • Organizations seeking a fully managed, cloud-native SIEM with minimal operational overhead
  • Small teams without dedicated security personnel or in-depth system administration skills
  • Environments requiring out-of-the-box integration with niche proprietary security tools not supported by Wazuh

Pros & Cons

Pros

Unified Threat Detection

Combines XDR and SIEM functionalities, including intrusion detection, log analysis, and vulnerability assessment, as outlined in its comprehensive capabilities list.

Broad Environment Support

Protects on-premises, virtualized, containerized, and cloud workloads with specific integrations for AWS, Azure, and Google Cloud, detailed in the cloud security section.

Open-Source Flexibility

Free under GPLv2 license with active community support, allowing for customization and avoiding vendor lock-in, evidenced by the GitHub repository and community channels.

Compliance-Ready Features

Provides built-in tools for meeting PCI DSS, GDPR, and other regulations, with dashboards and reports in the web user interface.

Extensive Automation Tools

Offers orchestration via Docker, Kubernetes, Ansible, and more, simplifying deployment in various environments, as listed in the orchestration section.

Cons

Complex Deployment and Management

Requires setting up and maintaining a central server, agents, and Elastic Stack integration, making it operationally intensive compared to turnkey solutions.

Dependency on Elastic Stack

For advanced data visualization and search, it relies on Elastic Stack, adding complexity and potential licensing costs if using Elastic's commercial features.

Resource Intensive on Endpoints

Agent-based monitoring can consume significant CPU and memory on monitored systems, which might impact performance in resource-constrained environments.

Steep Learning Curve

Mastering Wazuh's configuration, rules, and integrations requires substantial security and system administration expertise, as implied by the detailed documentation and setup guides.

Frequently Asked Questions

Quick Stats

Stars16,798
Forks2,473
Contributors0
Open Issues2,879
Last commit4 hours ago
CreatedSince 2015

Tags

#container-security#siem#malware-detection#infosec#vulnerability-detection#security#intrusion-detection#log-analysis#compliance#cybersecurity#cloud-security

Built With

O
OpenSSL
S
SQLite
c
curl
K
Kubernetes
P
Puppet
a
ansible
c
cJSON
C
Chef
R
RocksDB
A
AWS CloudFormation
D
Docker
L
Lua

Links & Resources

Website

Included in

Security14.2k
Auto-fetched 3 hours ago

Related Projects

CrowdSecCrowdSec

CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.

Stars14,787
Forks715
Last commit16 hours ago
opensnitchopensnitch

OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.

Stars14,043
Forks661
Last commit1 month ago
FibratusFibratus

Security sensor for realtime threat detection and protection

Stars2,539
Forks221
Last commit14 hours ago
FIRFIR

Fast Incident Response

Stars2,033
Forks514
Last commit1 day ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub