For an endpoint detection agent, the strongest matches are wazuh/wazuh (Wazuh is an open-source EDR platform that provides real-time), velocidex/velociraptor (Velociraptor is an endpoint detection and response platform that) and comodosecurity/openedr (OpenEDR is an endpoint detection and response platform that). ossec/ossec-hids and misp/misp round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
These tools provide real-time monitoring and automated threat detection for securing endpoints across your infrastructure.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is an open-source EDR platform that provides real-time endpoint monitoring, behavioral threat detection, automated active response actions, a centralized management console, multi-platform agent support, forensic data collection, and a full API — directly meeting the need for a deployable security agent with the requested capabilities.
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Velociraptor is an endpoint detection and response platform that deploys lightweight agents to collect forensic data and hunt for threats across a fleet of hosts, directly fitting the EDR agent query with its centralized management, multi-platform support, and investigative workflow, though it emphasizes forensic triage and hunting more than automated real-time prevention.
OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi
OpenEDR is an endpoint detection and response platform that collects system telemetry and monitors process, network, and file activity for behavioral threats, fitting the EDR agent category well, though explicit automated incident response and threat intelligence integration are not highlighted in its description.
OSSEC v4.1.0
OSSEC is a widely-used open-source host intrusion detection system that runs on endpoints, monitors system activity in real time, and can trigger automated responses, making it a legitimate endpoint detection and response (EDR) agent even if it focuses more on signature and log-based detection than behavioral analysis.
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
MISP is a threat intelligence sharing platform that centralizes and distributes structured threat indicators, not an endpoint agent that monitors systems and triggers responses — useful alongside EDR but not the agent itself.
Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.
Spectr3 is a forensic acquisition and analysis tool for remote block devices, not an agent that runs on endpoints to detect and respond to threats in real time — it fits the forensics part of the feature list but is the wrong type of tool for an EDR agent.
Picoclaw is a lightweight framework designed for the deployment and orchestration of autonomous software agents. It functions as a cross-platform runtime that packages the entire system into a single self-contained binary, enabling native execution across diverse hardware architectures including RISC-V, ARM64, and x86_64. The platform is specifically optimized for resource-constrained environments, ensuring minimal startup times and a low memory footprint. The system distinguishes itself through intelligent task orchestration, which routes incoming requests to specific inference models based
Picoclaw is a lightweight framework for deploying autonomous software agents with task orchestration and inference routing, but it does not include endpoint security monitoring, threat detection, or incident response capabilities that define an EDR agent.