Ross ROSS = Recommend OSS · open-source software intelligence for agents

Wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads. observed · 2026-08-28

github.com/wazuh/wazuh · homepage · C++ · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 95
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 28
  • age_days: 4040
  • days_rel: 34
  • days_push: 7
  • n_releases_24m: 22

Full methodology

Adoption not part of the score

16691 stars · 2455 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Wazuh is a free, open source security platform that unifies XDR and SIEM capabilities for threat prevention, detection, and response across endpoints, containers, and cloud workloads. It consists of an endpoint security agent plus central server, indexer, and dashboard components that collect, analyze, and visualize security telemetry.

Use cases

  • monitor security events across endpoints and cloud workloads
  • detect malware, rootkits, and intrusions on servers
  • collect and analyze logs from systems and applications
  • monitor file integrity and configuration changes
  • detect vulnerabilities on monitored hosts
  • meet PCI DSS and other regulatory compliance requirements
  • automate incident response on endpoints
  • hunt threats using telemetry and threat intelligence

When to choose

  • you need a free, self-hosted SIEM/XDR without license costs
  • you want unified endpoint, container, and cloud security monitoring in one agent
  • you must demonstrate regulatory compliance like PCI DSS
  • you need file integrity monitoring, vulnerability detection, and log analysis together
  • you want an open source alternative to commercial SIEM products

When to avoid

  • you need only a lightweight single-purpose tool rather than a full platform
  • you cannot run dedicated Linux servers for the central components
  • you require managed EDR with proprietary endpoint sensors and sandboxing
  • your team lacks capacity to operate and tune a security monitoring stack

Facets

application · maturity stable

security monitoring alerting logging search-engine vulnerability-scanning analytics security monitoring cloud-computing legal windows self-hosted cross-platform siem xdr hids file-integrity-monitoring intrusion-detection incident-response log-analysis threat-hunting pci-dss endpoint-security malware-detection compliance devops containers linux macos docker kubernetes

10 sources

Member repositories

RepositoryRoleHealth v2
wazuh/wazuhmain98
wazuh/wazuh-dockerinfra98

For agents

markdown · JSON · MCP: product_card(name="wazuh/wazuh")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem