0xrawsec/whids
Open Source EDR for Windows observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3144
- days_rel: n/a
- days_push: 1285
- n_releases_24m: 0
Adoption not part of the score
1311 stars · 149 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
WHIDS is an open-source Endpoint Detection and Response (EDR) tool for Windows, built on the Gene detection engine to match Sysmon/ETW events against user-defined rules. It supports detection-driven artifact collection (files, registry, process memory) and can run standalone or with an EDR manager.
Use cases
- detect threats on windows endpoints
- open source edr alternative
- threat hunting with sysmon events
- collect forensic artifacts on detection
- incident response endpoint monitoring
- write custom detection rules for windows event logs
When to choose
- you need a transparent, open-source EDR on Windows endpoints
- you want near real-time artifact collection triggered by detections
- you rely on Sysmon/ETW telemetry and want flexible rule-based detection
- you need a standalone agent without a commercial management console
When to avoid
- you need protection for Linux or macOS hosts
- you require a commercially supported EDR with SLAs
- you cannot install Sysmon on the monitored hosts
- you need actively maintained software with recent releases
Facets
application · maturity maintenance
security monitoring alerting logging security windows developer-tools windows go edr ids threat-hunting dfir sysmon etw incident-response detection-engine
2 sources
- readme: https://github.com/0xrawsec/whids · fetched 2026-08-28 · 66d38604ce3e
- homepage: https://rawsec.lu · fetched 2026-08-29 · f97972e2b773
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| 0xrawsec/whids | main | 23 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem