
Wazuh
Open-source XDR and SIEM platform for threat detection, response, and compliance.
About Wazuh
Wazuh is a free and open-source security platform for threat prevention, detection, and response. It combines SIEM log analysis with XDR endpoint monitoring to protect workloads across on-premises, virtualized, containerized, and cloud environments.
Wazuh agents run on each monitored system and forward security telemetry to a central manager, which correlates it against thousands of rules to detect intrusions, monitor file integrity, identify vulnerable software, and assess configuration compliance against standards like PCI DSS and GDPR.
Self-hosting Wazuh keeps your security telemetry on infrastructure you control, with no per-agent or per-gigabyte licensing. VPS1 deploys and manages the full stack, from manager and indexer to agents and dashboards.
Key Features
- SIEM log analysis and intrusion detection across servers and endpoints
- File integrity monitoring with user and application attribution
- Automated vulnerability detection correlated against live CVE databases
- Configuration assessment mapped to PCI DSS, GDPR, and hardening guides
Self-Hosting Notes
Find another tool
More in Security & Identity
Authelia
Comprehensive single sign-on (SSO) and multi-factor authentication (MFA) portal.
Authentik
Flexible, open-source identity provider supporting SSO, MFA, and enterprise federation.
Canarytokens
Self-hosted honeypot tokens that alert you when accessed. Detect breaches, insider threats, and credential exposure.
CrowdSec
Modern, collaborative intrusion prevention system built to detect bad behaviors.