Wazuh is an open-source, unified security platform that delivers extended detection and response (XDR) and SIEM capabilities for on-premises, cloud, container, and endpoint environments. It provides comprehensive threat prevention, detection, integrity monitoring, incident response, and compliance monitoring. SIEM functionality to monitor security across endpoints, workloads, and containers. Centralized architecture enabling scalable deployment and unified management. Easy deployment with rich documentation and community engagement.
Features
- Host-based intrusion detection (HIDS) with log analysis, integrity checking, rootkit detection, and alerting
- SIEM functionality to monitor security across endpoints, workloads, and containers
- Extensible modules (e.g., GitHub monitoring via audit log ingestion)
- Centralized architecture enabling scalable deployment and unified management
- Active tracking and mitigation of security advisories and vulnerabilities, with transparency on RCE or token exposure
- Easy deployment with rich documentation and community engagement
