# ossec/ossec-hids

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

Repository: https://github.com/ossec/ossec-hids
Canonical: https://ross.abutalabs.com/products/ossec-hids
Homepage: http://www.ossec.net
Language: C
License: GPL-2.0
License Family: copyleft
Topics: hids, security, pci-dss, nist800-53, ossec, compliance, intrusion-detection, fim, loganalyzer, policy-monitoring, file-integrity-management
Last push: 2026-08-26T19:38:32+00:00

## Health v2 (maintenance only)
Score: 91/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 75, longevity 100
- inputs: {"age_days": 4733, "days_push": 7, "days_rel": 8, "gap_med": 90.5, "n_releases_24m": 5}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5047, forks 1074 (observed 2026-08-28T04:09:08.910105+00:00)

## What it is
OSSEC is an open-source host-based intrusion detection system (HIDS) that combines log analysis, file integrity monitoring, rootkit detection, policy auditing, real-time alerting, and active response. It runs as a manager/agent platform across Unix, Linux, macOS, and Windows systems.

## Use cases
- detect intrusions on my servers from log files
- monitor file integrity and get alerted on changes
- check systems for rootkits and malware
- audit systems for compliance with PCI-DSS or NIST 800-53
- centralize security log monitoring across many hosts
- automatically respond to attacks like SSH brute force
- self-hosted SIEM alternative for small teams

## When to choose
- you need a free, self-hosted HIDS with manager/agent architecture
- you must meet compliance requirements like PCI-DSS or NIST 800-53
- you want file integrity monitoring, log analysis, and active response in one tool
- you need multi-platform coverage including Windows agents

## When to avoid
- you want a modern UI and ML-driven detection out of the box (consider Wazuh or OSSEC+)
- you need network-based intrusion detection rather than host-based
- you prefer a fully managed SaaS security monitoring service

## Facets
- artifact type: application
- maturity: stable
- function: monitoring, alerting, logging, security, search-engine
- domain: security, monitoring, legal, self-hosted
- platform: windows, cross-platform, self-hosted, cpp, c
- tags: hids, intrusion-detection, file-integrity-monitoring, rootkit-detection, log-analysis, siem, pci-dss, active-response, policy-monitoring, devops, linux, macos

## Member repositories
- ossec/ossec-hids (main) score 91

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:08.910105+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:17:22.588150+00:00, confidence not recorded.
  - readme: https://github.com/ossec/ossec-hids (fetched 2026-08-28T04:09:08.910105+00:00, sha daf4a39dcf1d)
  - homepage: http://www.ossec.net (fetched 2026-08-29T08:58:01.050475+00:00, sha ce82f5d627eb)
  - site_page: https://www.ossec.net/docs (fetched 2026-08-29T08:58:01.061582+00:00, sha 63418963bad3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
