awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
wazuh avatar

wazuh/wazuh

0
View on GitHub↗
wazuh.com↗

Wazuh

Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity.

The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monitoring and malware detection, while simultaneously evaluating configurations and software versions against established security benchmarks and threat databases.

Beyond core detection, the platform supports comprehensive regulatory compliance auditing and user access management. It monitors both traditional endpoints and ephemeral cloud or containerized environments, providing a unified interface for security teams to identify patterns, enforce policies, and automate incident response actions.

Features

  • Operations and Incident Response - Provides an integrated security agent for endpoint detection, file integrity monitoring, and automated incident response.
  • Security Information Management - Aggregates log data and endpoint telemetry to provide centralized visibility and threat detection.
  • Cloud Security Monitoring - Monitors ephemeral cloud and containerized environments to detect misconfigurations and enforce security policies.
  • Cloud Infrastructure Security - Maintains visibility into cloud workloads and container environments to detect threats and ensure secure configurations.
  • Container Security - Maintains visibility into cloud and container environments to detect threats and enforce consistent security policies.

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI
14,779 Stars·2,163 Forks·C·other·29 Aufrufe
  • Vulnerability Scanners - Identifies known security weaknesses and missing software updates across distributed systems to maintain infrastructure integrity.
  • Centralized Logging Systems - Aggregates and normalizes heterogeneous logs from distributed infrastructure into a unified format for security analysis.
  • Endpoint Monitoring Agents - Deploys lightweight agents to endpoints for continuous system activity monitoring and telemetry streaming.
  • Event-Based Triggers - Triggers automated scripts on remote endpoints to neutralize security threats in real time.
  • Audit and Compliance - Maps security events and system configurations against industry standards to verify regulatory compliance.
  • Security and Compliance - The platform maps security events and system configurations against industry standards to generate reports and verify adherence to security policies.
  • Infrastructure and System Hardening - Evaluates system settings against security benchmarks and scans for weaknesses to maintain a hardened infrastructure.
  • Vulnerability Scanning - Scans systems and applications for known security weaknesses and missing updates to ensure a hardened infrastructure.
  • Telemetry Correlation Engines - Evaluates incoming telemetry against predefined logic to identify complex attack patterns and policy violations.
  • File System Monitors - A kernel-level or system-call-based observer tracks real-time modifications to critical files to detect unauthorized changes or malicious activity.
  • Automated Incident Response Workflows - Executes automated actions like blocking network traffic or terminating malicious processes to neutralize active threats.
  • Log Analysis - Parses and interprets log data from various sources to extract actionable security insights and identify suspicious patterns.
  • Endpoint Monitoring Tools - Comprehensive security platform for endpoint protection.
  • Infrastructure Monitoring - Open-source security platform for XDR and SIEM.
  • Monitoring and Status - Unified XDR and SIEM protection for endpoints.
  • Monitoring Systems - Unified XDR and SIEM protection platform.
  • Security Lab Environments - Unified XDR and SIEM platform for threat detection and response.
  • Continuous Security Monitoring - Platform for security monitoring and threat detection.
  • Intrusion Detection Systems - Platform for threat prevention, detection, and response.
  • Sicherheit und Datenschutz - Unified XDR and SIEM security platform.
  • Security & Privacy - Security monitoring and SIEM.
  • Security Configurations - The platform evaluates system settings against established security benchmarks to identify misconfigurations and ensure adherence to hardening standards.
  • Threat Detection - The platform identifies malicious software by scanning files and observing system behavior to match against known threat signatures and patterns.
  • Vulnerability Assessment Frameworks - Systematically scans software versions and configurations against threat databases to identify security weaknesses.
  • User Access Management - The platform controls system access through role-based permissions and connects with external identity providers to centralize user authentication.
  • Star-Verlauf

    Star-Verlauf für wazuh/wazuhStar-Verlauf für wazuh/wazuh

    Häufig gestellte Fragen

    Was macht wazuh/wazuh?

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity.

    Was sind die Hauptfunktionen von wazuh/wazuh?

    Die Hauptfunktionen von wazuh/wazuh sind: Operations and Incident Response, Security Information Management, Cloud Security Monitoring, Cloud Infrastructure Security, Container Security, Vulnerability Scanners, Centralized Logging Systems, Endpoint Monitoring Agents.

    Welche Open-Source-Alternativen gibt es zu wazuh/wazuh?

    Open-Source-Alternativen zu wazuh/wazuh sind unter anderem: sbilly/awesome-security — This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… boto/boto3 — Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud… projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure…

    Open-Source-Alternativen zu Wazuh

    Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Wazuh.
    • sbilly/awesome-securityAvatar von sbilly

      sbilly/awesome-security

      14,022Auf GitHub ansehen↗

      This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

      awesome-listsecurity
      Auf GitHub ansehen↗14,022
    • crowdsecurity/crowdsecAvatar von crowdsecurity

      crowdsecurity/crowdsec

      12,574Auf GitHub ansehen↗

      CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

      Goattacks-preventiondetectionids
      Auf GitHub ansehen↗12,574
    • aws/aws-cdkAvatar von aws

      aws/aws-cdk

      12,817Auf GitHub ansehen↗

      The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

      TypeScriptawscloud-infrastructurehacktoberfest
      Auf GitHub ansehen↗12,817
    • falcosecurity/falcoAvatar von falcosecurity

      falcosecurity/falco

      8,670Auf GitHub ansehen↗

      Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

      C++cloud-nativecncfcncf-project
      Auf GitHub ansehen↗8,670
    Alle 30 Alternativen zu Wazuh anzeigen→