awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Open Source Endpoint Detection Response

Ranking updated Jun 30, 2026

For an endpoint detection agent, the strongest matches are wazuh/wazuh (Wazuh is an open-source EDR platform that provides real-time), velocidex/velociraptor (Velociraptor is an endpoint detection and response platform that) and comodosecurity/openedr (OpenEDR is an endpoint detection and response platform that). ossec/ossec-hids and misp/misp round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

These tools provide real-time monitoring and automated threat detection for securing endpoints across your infrastructure.

Open Source Endpoint Detection Response

Find the best repos with AI.We'll search the best matching repositories with AI.
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Wazuh is an open-source EDR platform that provides real-time endpoint monitoring, behavioral threat detection, automated active response actions, a centralized management console, multi-platform agent support, forensic data collection, and a full API — directly meeting the need for a deployable security agent with the requested capabilities.

    COperations and Incident ResponseSecurity Information ManagementCloud Security Monitoring
    View on GitHub↗14,779
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Velociraptor is an endpoint detection and response platform that deploys lightweight agents to collect forensic data and hunt for threats across a fleet of hosts, directly fitting the EDR agent query with its centralized management, multi-platform support, and investigative workflow, though it emphasizes forensic triage and hunting more than automated real-time prevention.

    GoEvidence CollectionForensic Evidence Preservation
    View on GitHub↗3,769
  • comodosecurity/openedrComodoSecurity avatar

    ComodoSecurity/openedr

    2,603View on GitHub↗

    OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi

    OpenEDR is an endpoint detection and response platform that collects system telemetry and monitors process, network, and file activity for behavioral threats, fitting the EDR agent category well, though explicit automated incident response and threat intelligence integration are not highlighted in its description.

    C++Endpoint Detection and ResponseIntrusion Detection SystemsTelemetry Collection and Aggregation
    View on GitHub↗2,603
  • ossec/ossec-hidsO

    ossec/ossec-hids

    0View on GitHub↗

    OSSEC v4.1.0

    OSSEC is a widely-used open-source host intrusion detection system that runs on endpoints, monitors system activity in real time, and can trigger automated responses, making it a legitimate endpoint detection and response (EDR) agent even if it focuses more on signature and log-based detection than behavioral analysis.

    Endpoint Monitoring ToolsInfrastructure and MonitoringSecurity & Privacy
    View on GitHub↗0
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    MISP is a threat intelligence sharing platform that centralizes and distributes structured threat indicators, not an endpoint agent that monitors systems and triggers responses — useful alongside EDR but not the agent itself.

    PHPTAXII ExchangesThreat IntelligenceThreat Intelligence
    View on GitHub↗6,360
  • alpine-sec/spectr3alpine-sec avatar

    alpine-sec/SPECTR3

    44View on GitHub↗

    Forensic tool for acquisition, triage and analysis of remote block devices via iSCSI protocol.

    Spectr3 is a forensic acquisition and analysis tool for remote block devices, not an agent that runs on endpoints to detect and respond to threats in real time — it fits the forensics part of the feature list but is the wrong type of tool for an EDR agent.

    C#Evidence Collection
    View on GitHub↗44
  • sipeed/picoclawsipeed avatar

    sipeed/picoclaw

    29,430View on GitHub↗

    Picoclaw is a lightweight framework designed for the deployment and orchestration of autonomous software agents. It functions as a cross-platform runtime that packages the entire system into a single self-contained binary, enabling native execution across diverse hardware architectures including RISC-V, ARM64, and x86_64. The platform is specifically optimized for resource-constrained environments, ensuring minimal startup times and a low memory footprint. The system distinguishes itself through intelligent task orchestration, which routes incoming requests to specific inference models based

    Picoclaw is a lightweight framework for deploying autonomous software agents with task orchestration and inference routing, but it does not include endpoint security monitoring, threat detection, or incident response capabilities that define an EDR agent.

    GoExternal Tool Integrations
    View on GitHub↗29,430

Related searches

  • an endpoint querying agent
  • an open source antivirus for system protection
  • an open source malware scanner and remover
  • an open source SIEM for log analysis
  • an intrusion detection system
  • an open source file and url scanner
  • a forensic triage tool
  • an autonomous framework for penetration testing