awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
wazuh avatar

wazuh/wazuh

0
View on GitHub↗
14,779 stars·2,163 forks·C·other·63 viewswazuh.com↗

Wazuh

Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity.

The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monitoring and malware detection, while simultaneously evaluating configurations and software versions against established security benchmarks and threat databases.

Beyond core detection, the platform supports comprehensive regulatory compliance auditing and user access management. It monitors both traditional endpoints and ephemeral cloud or containerized environments, providing a unified interface for security teams to identify patterns, enforce policies, and automate incident response actions.

Features

  • Operations and Incident Response - Provides an integrated security agent for endpoint detection, file integrity monitoring, and automated incident response.
  • Security Information Management - Aggregates log data and endpoint telemetry to provide centralized visibility and threat detection.
  • Cloud Security Monitoring - Monitors ephemeral cloud and containerized environments to detect misconfigurations and enforce security policies.
  • Cloud Infrastructure Security - Maintains visibility into cloud workloads and container environments to detect threats and ensure secure configurations.
  • Container Security - Maintains visibility into cloud and container environments to detect threats and enforce consistent security policies.
  • Vulnerability Scanners - Identifies known security weaknesses and missing software updates across distributed systems to maintain infrastructure integrity.
  • Centralized Logging Systems - Aggregates and normalizes heterogeneous logs from distributed infrastructure into a unified format for security analysis.
  • Endpoint Monitoring Agents - Deploys lightweight agents to endpoints for continuous system activity monitoring and telemetry streaming.
  • Event-Based Triggers - Triggers automated scripts on remote endpoints to neutralize security threats in real time.
  • Audit and Compliance - Maps security events and system configurations against industry standards to verify regulatory compliance.
  • Security and Compliance - The platform maps security events and system configurations against industry standards to generate reports and verify adherence to security policies.
  • Infrastructure and System Hardening - Evaluates system settings against security benchmarks and scans for weaknesses to maintain a hardened infrastructure.
  • Vulnerability Scanning - Scans systems and applications for known security weaknesses and missing updates to ensure a hardened infrastructure.
  • Telemetry Correlation Engines - Evaluates incoming telemetry against predefined logic to identify complex attack patterns and policy violations.
  • File System Monitors - A kernel-level or system-call-based observer tracks real-time modifications to critical files to detect unauthorized changes or malicious activity.
  • Automated Incident Response Workflows - Executes automated actions like blocking network traffic or terminating malicious processes to neutralize active threats.
  • Log Analysis - Parses and interprets log data from various sources to extract actionable security insights and identify suspicious patterns.
  • Endpoint Monitoring Tools - Comprehensive security platform for endpoint protection.
  • Infrastructure Monitoring - Open-source security platform for XDR and SIEM.
  • Monitoring and Status - Unified XDR and SIEM protection for endpoints.
  • Monitoring Systems - Unified XDR and SIEM protection platform.
  • Security Lab Environments - Unified XDR and SIEM platform for threat detection and response.
  • Continuous Security Monitoring - Platform for security monitoring and threat detection.
  • Intrusion Detection Systems - Platform for threat prevention, detection, and response.
  • Security And Privacy - Unified XDR and SIEM security platform.
  • Security & Privacy - Security monitoring and SIEM.
  • Security Configurations - The platform evaluates system settings against established security benchmarks to identify misconfigurations and ensure adherence to hardening standards.
  • Threat Detection - The platform identifies malicious software by scanning files and observing system behavior to match against known threat signatures and patterns.
  • Vulnerability Assessment Frameworks - Systematically scans software versions and configurations against threat databases to identify security weaknesses.
  • User Access Management - The platform controls system access through role-based permissions and connects with external identity providers to centralize user authentication.

Star history

Star history chart for wazuh/wazuhStar history chart for wazuh/wazuh

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Wazuh

These projects share indexed features with Wazuh. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • sbilly/awesome-securitysbilly avatar

    sbilly/awesome-security

    14,022View on GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    awesome-listsecurity
    View on GitHub↗14,022
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    View on GitHub↗12,574
  • aws/aws-cdkaws avatar

    aws/aws-cdk

    12,817View on GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    View on GitHub↗12,817
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
Compare all 30 related projects→

Frequently asked questions

What does wazuh/wazuh do?

Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity.

What are the main features of wazuh/wazuh?

The main features of wazuh/wazuh are: Operations and Incident Response, Security Information Management, Cloud Security Monitoring, Cloud Infrastructure Security, Container Security, Vulnerability Scanners, Centralized Logging Systems, Endpoint Monitoring Agents.

Which projects share features with wazuh/wazuh?

Projects with overlapping indexed features include: sbilly/awesome-security — This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to… crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… boto/boto3 — Boto3 is the AWS SDK for Python, providing a programmatic interface for managing and automating AWS cloud… projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure…