OSSEC

An open-source host-based intrusion detection system with log analysis, file integrity monitoring and active response.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About OSSEC

OSSEC is a host-based intrusion detection system (HIDS) that analyses logs on multiple platforms. It also monitors file integrity, detects malware, runs compliance audits and can respond to threats automatically. You tailor it through configuration options, custom alert rules and scripts.

Atomicorp manages and develops the project. A free registered edition, OSSEC+, adds a machine learning system, ELK stack and OpenSearch integration, real-time threat intelligence and thousands of extra rules.

Strengths

  • Combines log analysis, file integrity monitoring and active response
  • Custom rules and scripts for tailored alerting
  • Actively developed by Atomicorp

Limitations

  • Configuration takes time to learn
  • Extra features such as machine learning need registration for OSSEC+

Details

Pricing
FreeFree and open source; the OSSEC+ edition is also free after registration.
License
Open source, license not stated
Developer
Atomicorp
Platforms
Self-hosted
How it runs
Self-hosted
Account
Not required
Best suited for
Administrators watching servers for intrusions and unexpected file changes
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to OSSEC

Compare all

Software that can replace OSSEC for an important use case, and what changes if you switch.

  • Wazuh Agent

    Endpoint agent that feeds a Wazuh server with security and compliance data.

    Wazuh Agent covers file integrity monitoring, log collection, rootkit detection and configuration assessment on Windows and Linux, but needs a Wazuh manager and indexer.

  • AIDE

    A file and directory integrity checker that records file attributes and hashes, then reports changes.

    AIDE covers only file integrity checking with hashes and attributes on Linux, without log analysis or active response, and it has no graphical interface.

  • CrowdSec

    Detect suspicious behavior in server logs and web traffic.

    CrowdSec is an MIT tool that detects suspicious behaviour in server logs and web traffic with community intelligence, but lacks file integrity monitoring and needs enforcement integrations.

OSSEC as an alternative

Listings that name OSSEC as an alternative.

  • chkrootkit

    A command-line tool that checks Unix-like systems locally for signs of a rootkit.

    OSSEC is a self-hosted host intrusion detection system combining log analysis, file integrity monitoring and rootkit detection with active response, beyond chkrootkit's local checks.

  • Fail2ban

    Log-watching daemon that bans addresses after repeated authentication failures.

    OSSEC is a self-hosted host intrusion detection system that combines log analysis with file integrity monitoring and active response, giving broader coverage with more configuration to learn.

  • Velociraptor

    Endpoint monitoring and digital forensics platform driven by a query language.

    OSSEC is a self-hosted host intrusion detection system with log analysis, file integrity monitoring and active response, but it has no query language for collecting arbitrary host state.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing