Velociraptor is an open-source endpoint visibility and collection tool using VQL queries for advanced incident response and digital forensic...
Wazuh
Wazuh is the leading open-source SIEM and XDR platform that unifies threat prevention, detection, and response across endpoints, cloud, and container environments.
Security Operations
open-source
siem
xdr
host-based-intrusion-detection
Overview
Wazuh is a free and open-source security platform that unifies SIEM and XDR capabilities for threat prevention, detection, and response across on-premises, virtualized, containerized, and cloud environments. It deploys lightweight agents to collect security data from endpoints, then centralizes analysis, correlation, and alerting on a manager node. Wazuh includes File Integrity Monitoring (FIM), vulnerability detection via CVE correlation, Security Configuration Assessment (SCA) against CIS benchmarks, rootkit and malware detection, active response, and full cloud-native integrations with AWS, Azure, and Google Cloud. It was named the 2026 Cybersecurity Stars Award winner for Best Cloud Security Platform.
Primary Use Cases
✔
Centralizing and correlating log data from endpoints, servers, cloud services, and network devices for real-time security event monitoring and alerting.
✔
File Integrity Monitoring (FIM) to detect unauthorized changes to critical files, directories, and Windows Registry keys across monitored endpoints.
✔
Vulnerability detection by correlating installed software inventory on monitored endpoints with CVE databases to surface known exploitable flaws.
Frequently Asked Questions
Yes. Wazuh is free and open-source software licensed under GPL v2, with no licensing fees, no per-agent costs, and no data ingestion limits, making it a popular alternative to commercial SIEM platforms.
As of September 2026, the current stable release is Wazuh 4.14.x, with Wazuh 5.0 in beta and expected to reach general availability later in 2026. The project publishes regular patch and minor releases on its official GitHub repository.
Yes. Wazuh provides native integrations with AWS, Microsoft Azure, and Google Cloud Platform, allowing it to collect and analyze cloud service logs, monitor configuration changes, and detect threats across cloud infrastructure alongside on-premises assets.
Wazuh is fully open-source under GPL v2 with no licensing costs and no data ingestion limits, whereas Splunk operates on a commercial license and Elastic uses an open-core model (Elastic License / SSPL) with usage-based pricing tiers. Wazuh also ships with built-in HIDS, FIM, SCA, and vulnerability detection out of the box rather than requiring separate modules.
Yes. Wazuh has native Docker and Kubernetes integrations that monitor container behavior, images, volumes, and orchestration events, and it supports agentless monitoring for environments where installing an agent is not practical. Security events from containers are correlated with host and cloud telemetry in the same SIEM pipeline.
Metadata
Official Website
Visit Website
Category Info
Security Operations covers the tools, platforms, and workflows used by SOC and blue teams to continuously monitor, detect, investigate, and respond to threats across endpoints, networks, and cloud infrastructure.
Added On
September 16, 2026
Last Updated
September 16, 2026
Related Security & OSINT Tools
Security Operations
Security Operations
Intezer is an AI-powered SOC platform that won Best Autonomous Security Operations Platform 2026, providing forensic-grade AI for alert tria...
Threat Detection
MITRE ATT&CK Navigator is a free web-based tool for visualizing, annotating, and comparing coverage of adversary tactics and techniques from...