Discover / Security

Wazuh

by wazuhC++

Open-source security platform for threat detection, XDR and SIEM.

Toolstable

Maturity: stable because 11y old, v4.14.7 released 4d ago. Derived from release and commit history, not a rating.

Stars
16k
Forks
2.4k
Downloads / mo
Last commit
2026-08-02
License
NOASSERTION
Open issues
3.0k

Market and trust evidence

Edition not yet matched

No exact skills.sh identity match is available for this repository. Repository adoption and freshness remain visible above; install momentum is not inferred.

Trust analysis is a screening signal, not a security warranty. Read the ranking and trust methodology.

In practice

Written by AI from this repository’s README · high confidence

Security teams lack unified visibility over logs, file changes and vulnerabilities across on premises, container and cloud workloads.

Use it when

When you want self hosted XDR and SIEM coverage with agents on endpoints and a central server that correlates and alerts.

Not the right pick when

Wrong pick for a quick single host check, since it means deploying agents plus a management server and the Elastic Stack.

Capabilities

  • intrusion detection scanning for malware, rootkits and anomalies
  • log data analysis with rule based correlation on a central manager
  • file integrity monitoring of content, permissions and ownership
  • vulnerability detection correlated against CVE databases
  • configuration assessment against policies and hardening guides
  • active response and remote command execution on agents

Cost: Free and open source

Video walkthroughs

Third-party YouTube uploads matched to this tool by title, channel and repository name on 2026-08-03. Not made, reviewed or endorsed by SkillPilot. View counts and publish months are as of the match date and the month is approximate. Nothing loads from YouTube until you press play.

What the repository ships

Has testsHas docsSecurity policyCI configured

Detected from the actual files in the repository root.

Latest release v4.14.7

Published 2026-07-30

Manager

Removed
  • Removed deprecated wazuh-dbd daemon and database_output configuration. (#37035)
Fixed
  • Improved cluster payload buffer allocation strategy. (#37280)
  • Improved cluster archive decompression limits. (#37119)
  • Improved cluster worker file path validation. (#36998)
  • Improved API authentication stability with bounded thread pools, regex timeouts and payload size limits. (#37034)
  • Updated aiohttp, cryptography, PyJWT, python-multipart and starlette Python dependencies. (#37361)

Agent

Fixed
  • Fixed AWS SQS subscriber wodle resolving the wrong AWS account for cross-account iam_role_arn configurations. (#36791)
  • Fixed agent keepalive scheduling after a system clock rollback causing false Disconnected status. (#36338)
  • Fixed eBPF FIM whodata dropping file events on older kernels such as Amazon Linux 2 and 2023. (#37014)
  • Fixed eBPF FIM whodata missing file move/rename events into monitored folders. (#37023)
  • Added IP address validation to the ip-customblock active response to prevent malformed input in file path operations. (#36730)
  • Added a null check for inode and device fields in the FIM whodata event handler. (#37245)

Ruleset

Fixed
  • Fixed multiple Debian, Ubuntu and Windows SCA checks generating incorrect results. (#37385)
  • Fixed a typo in the SELinux SCA check causing false failures on CentOS 8, 9 and 10 systems configured as permissive. (#36361)
  • Fixed the AlmaLinux 9 and 10 bootloader permissions SCA check regex and optional file handling. (#36396)
  • Fixed the /etc/gshadow- permissions SCA check always failing due to an incorrect all condition. (#36795)
  • Fixed a macOS SCA PolicyBanner check false failure by wrapping the command in sh -c for glob expansion. (#36783)

RESTful API

Fixed
  • Fixed TypeError when sorting agents by version with empty version strings. (#37323)
  • Improved sensitive data masking in cluster configuration endpoint. (#37039)

Tags

README

Wazuh

Slack

Email

Documentation

Documentation

Coverity

Twitter

YouTube

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments.

Wazuh solution consists of an endpoint security agent, deployed to the monitored systems, and a management server, which collects and analyzes data gathered by the agents. Besides, Wazuh has been fully integrated with the Elastic Stack, providing a search engine and data visualization tool that allows users to navigate through their security alerts.

Wazuh capabilities

A brief presentation of some of the more common use cases of the Wazuh solution.

Intrusion detection

Wazuh agents scan the monitored systems looking for malware, rootkits and suspicious anomalies. They can detect hidden files, cloaked processes or unregistered network listeners, as well as inconsistencies in system call responses.

In addition to agent capabilities, the server component uses a signature-based approach to intrusion detection, using its regular expression engine to analyze collected log data and look for indicators of compromise.

Log data analysis

Wazuh agents read operating system and application logs, and securely forward them to a central manager for rule-based analysis and storage. When no agent is deployed, the server can also receive data via syslog from network devices or applications.

The Wazuh rules help make you aware of application or system errors, misconfigurations, attempted and/or successful malicious activities, policy violations and a variety of other security and operational issues.

File integrity monitoring

Wazuh monitors the file system, identifying changes in content, permissions, ownership, and attributes of files that you need to keep an eye on. In addition, it natively identifies users and applications used to create or modify files.

File integrity monitoring capabilities can be used in combination with threat intelligence to identify threats or compromised hosts. In addition, several regulatory compliance standards, such as PCI DSS, require it.

Vulnerability detection

Wazuh agents pull software inventory data and send this information to the server, where it is correlated with continuously updated CVE (Common Vulnerabilities and Exposure) databases, in order to identify well-known vulnerable software.

Automated vulnerability assessment helps you find the weak spots in your critical assets and take corrective action before attackers exploit them to sabotage your business or steal confidential data.

Configuration assessment

Wazuh monitors system and application configuration settings to ensure they are compliant with your security policies, standards and/or hardening guides. Agents perform periodic scans to detect applications that are known to be vulnerable, unpatched, or insecurely configured.

Additionally, configuration checks can be customized, tailoring them to properly align with your organization. Alerts include recommendations for better configuration, references and mapping with regulatory compliance.

Incident response

Wazuh agents provide out-of-the-box active responses to perform various countermeasures to address active threats, such as blocking access to a system from the threat source when certain criteria are met.

In addition, Wazuh can be used to remotely run commands or system queries on agents, identifying indicators of compromise (IOCs) and helping perform other live forensics or incident response tasks.

Regulatory compliance

Wazuh provides some of the necessary security controls to become compliant with industry standards and regulations. These features, combined with its scalability and multi-platform support help organizations meet technical compliance requirements.

Wazuh is widely used by payment processing companies and financial institutions to meet PCI DSS (Payment Card Industry Data Security Standard) requirements. Its web user interface provides reports and dashboards that can help with this and other regulations (e.g. GPG13 or GDPR).

Cloud security

Wazuh helps monitoring cloud infrastructure at an API level, using integration modules that are able to pull security data from well known cloud providers, such as Amazon AWS, Azure or Google Cloud. In addition, Wazuh provides rules to assess the configuration of your cloud environment, easily spotting weaknesses.

In addition, Wazuh light-weight and multi-platform agents are commonly used to monitor cloud environments at the instance level.

Containers security

Wazuh provides security visibility into your Docker hosts and containers, monitoring their behavior and detecting threats, vulnerabilities and anomalies. The Wazuh agent has native integration with the Docker engine allowing users to monitor images, volumes, network settings, and running containers.

Wazuh continuously collects and analyzes detailed runtime information. For example, alerting for containers running in privileged mode, vulnerable applications, a shell running in a container, changes to persistent volumes or images, and other possible threats.

WUI

The Wazuh WUI provides a powerful user interface for data visualization and analysis. This interface can also be used to manage Wazuh configuration and to monitor its status.

Modules overview

Modules overview

Security events

Overview

Integrity monitoring

Overview

Vulnerability detection

Overview

Regulatory compliance

Overview

Agents overview

Overview

Agent summary

Overview

Orchestration

Here you can find all the automation tools maintained by the Wazuh team.

Branches

  • main branch contains the latest code, be aware of possible bugs on this branch.

Software and libraries used

| Software | Version | Author | License |

| ----------------------------------------------------------------------- | ------- | ----------------------------- | --------------------------------------------- |

| bpftool | 7.7.0 | libbpf | GNU Public License version 2 |

| bzip2 | 1.0.8 | Julian Seward | BSD License |

| cJSON | 1.7.18 | Dave Gamble | MIT License |

| cpp-httplib | 0.25.0 | yhirose | MIT License |

| cPython | 3.12.13 | Guido van Rossum | Python Software Foundation License version 2 |

| cURL | 8.20.0 | Daniel Stenberg | MIT License |

| dbus | 1.14.10 | freedesktop.org | GNU Public License version 2 |

| Flatbuffers | 23.5.26 | Google Inc. | Apache 2.0 License |

| Google Benchmark | 1.6.1 | Google Inc. | Apache 2.0 License | |

| GoogleTest | 1.11.0 | Google Inc. | 3-Clause "New" BSD License |

| jemalloc | 5.2.1 | Jason Evans | 2-Clause "Simplified" BSD License |

| libarchive | 3.8.7 | Tim Kientzle | 3-Clause "New" BSD License |

| libbpf | 1.7.0 | libbpf | GNU Lesser General Public License version 2.1 |

| libdb | 18.1.40 | Oracle Corporation | Affero GPL v3 |

| libffi | 3.2.1 | Anthony Green | MIT License |

| libpcre2 | 10.42.0 | Philip Hazel | BSD License |

| libplist | 2.2.0 | Aaron Burghardt et al. | GNU Lesser General Public License version 2.1 |

| libYAML | 0.1.7 | Kirill Simonov | MIT License |

| liblzma | 5.8.3 | Lasse Collin, Jia Tan et al. | GNU Public License version 3 |

| Linux Audit userspace | 2.8.4 | Rik Faith | GNU Lesser General Public License |

| Lua | 5.4.8 | PUC-Rio | MIT License |

| nlohmann | 3.11.2 | Niels Lohmann | MIT License |

| OpenSSL | 3.6.2 | OpenSSL Software Foundation | Apache 2.0 License |

| popt | 1.16 | Jeff Johnson & Erik Troan | MIT License |

| procps | 2.8.3 | Brian Edmonds et al. | GNU Lesser General Public License |

| RocksDB | 8.3.2 | Facebook Inc. | Apache 2.0 License |

| rpm | 4.20.1 | Marc Ewing & Erik Troan | GNU Public License version 2 |

| simdjson | 3.13.0 | Daniel Lemire | Apache License 2.0 |

| sqlite | 3.53.1 | D. Richard Hipp | Public Domain (no restrictions) |

| zlib | 1.3.1 | Jean-loup Gailly & Mark Adler | zlib/libpng License |

  • PyPi packages

Documentation

Get involved

Become part of the Wazuh's community to learn from other users, participate in discussions, talk to our developers and contribute to the project.

If you want to contribute to our project please don’t hesitate to make pull-requests, submit issues or send commits, we will review all your questions.

You can also join our Slack community channel and mailing list by sending an email to wazuh+subscribe@googlegroups.com, to ask questions and participate in discussions.

Stay up to date on news, releases, engineering articles and more.

Truncated. Read the full README on GitHub ↗

Related tools