# 0xrawsec/whids

Open Source EDR for Windows

Repository: https://github.com/0xrawsec/whids
Canonical: https://ross.abutalabs.com/products/whids
Homepage: https://rawsec.lu
Language: Go
License: AGPL-3.0
License Family: copyleft
Topics: dfir, threat-hunting, windows, ids, sysmon, edr
Last push: 2023-02-25T03:59:03+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3144, "days_push": 1285, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1311, forks 149 (observed 2026-08-28T04:04:19.979738+00:00)

## What it is
WHIDS is an open-source Endpoint Detection and Response (EDR) tool for Windows, built on the Gene detection engine to match Sysmon/ETW events against user-defined rules. It supports detection-driven artifact collection (files, registry, process memory) and can run standalone or with an EDR manager.

## Use cases
- detect threats on windows endpoints
- open source edr alternative
- threat hunting with sysmon events
- collect forensic artifacts on detection
- incident response endpoint monitoring
- write custom detection rules for windows event logs

## When to choose
- you need a transparent, open-source EDR on Windows endpoints
- you want near real-time artifact collection triggered by detections
- you rely on Sysmon/ETW telemetry and want flexible rule-based detection
- you need a standalone agent without a commercial management console

## When to avoid
- you need protection for Linux or macOS hosts
- you require a commercially supported EDR with SLAs
- you cannot install Sysmon on the monitored hosts
- you need actively maintained software with recent releases

## Facets
- artifact type: application
- maturity: maintenance
- function: security, monitoring, alerting, logging
- domain: security, windows, developer-tools
- platform: windows, go
- tags: edr, ids, threat-hunting, dfir, sysmon, etw, incident-response, detection-engine

## Member repositories
- 0xrawsec/whids (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.979738+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:49:48.840533+00:00, confidence not recorded.
  - readme: https://github.com/0xrawsec/whids (fetched 2026-08-28T04:04:19.979738+00:00, sha 66d38604ce3e)
  - homepage: https://rawsec.lu (fetched 2026-08-29T12:07:40.095491+00:00, sha f97972e2b773)
- Data as of 2026-08-30T08:39:29.467469+00:00.
