OSSEC
An open-source host-based intrusion detection system with log analysis, file integrity monitoring and active response.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About OSSEC
OSSEC is a host-based intrusion detection system (HIDS) that analyses logs on multiple platforms. It also monitors file integrity, detects malware, runs compliance audits and can respond to threats automatically. You tailor it through configuration options, custom alert rules and scripts.
Atomicorp manages and develops the project. A free registered edition, OSSEC+, adds a machine learning system, ELK stack and OpenSearch integration, real-time threat intelligence and thousands of extra rules.
Strengths
- Combines log analysis, file integrity monitoring and active response
- Custom rules and scripts for tailored alerting
- Actively developed by Atomicorp
Limitations
- Configuration takes time to learn
- Extra features such as machine learning need registration for OSSEC+
Details
- Pricing
- FreeFree and open source; the OSSEC+ edition is also free after registration.
- License
- Open source, license not stated
- Developer
- Atomicorp
- Platforms
- Self-hosted
- How it runs
- Self-hosted
- Account
- Not required
- Best suited for
- Administrators watching servers for intrusions and unexpected file changes
- Categories
- Security tools, IT administration
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to OSSEC
Compare allSoftware that can replace OSSEC for an important use case, and what changes if you switch.
Wazuh Agent
Endpoint agent that feeds a Wazuh server with security and compliance data.
Wazuh Agent covers file integrity monitoring, log collection, rootkit detection and configuration assessment on Windows and Linux, but needs a Wazuh manager and indexer.
AIDE
A file and directory integrity checker that records file attributes and hashes, then reports changes.
AIDE covers only file integrity checking with hashes and attributes on Linux, without log analysis or active response, and it has no graphical interface.
CrowdSec
Detect suspicious behavior in server logs and web traffic.
CrowdSec is an MIT tool that detects suspicious behaviour in server logs and web traffic with community intelligence, but lacks file integrity monitoring and needs enforcement integrations.
OSSEC as an alternative
Listings that name OSSEC as an alternative.
chkrootkit
A command-line tool that checks Unix-like systems locally for signs of a rootkit.
OSSEC is a self-hosted host intrusion detection system combining log analysis, file integrity monitoring and rootkit detection with active response, beyond chkrootkit's local checks.
Fail2ban
Log-watching daemon that bans addresses after repeated authentication failures.
OSSEC is a self-hosted host intrusion detection system that combines log analysis with file integrity monitoring and active response, giving broader coverage with more configuration to learn.
Velociraptor
Endpoint monitoring and digital forensics platform driven by a query language.
OSSEC is a self-hosted host intrusion detection system with log analysis, file integrity monitoring and active response, but it has no query language for collecting arbitrary host state.
Similar software
Related functionality, not necessarily a direct replacement.