Wazuh
Overview
Wazuh is a free and open source security platform that unifies Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) protection for endpoints and cloud workloads. It provides threat prevention, detection, and response capabilities across on-premises, virtualized, containerized, and cloud-based environments.
Key Features
- Unified XDR and SIEM: Combines endpoint detection and response with security information and event management in a single platform
- Threat Intelligence: Integrates with threat intelligence feeds for real-time threat detection
- File Integrity Monitoring: Tracks changes to critical system files and directories
- Vulnerability Detection: Identifies known vulnerabilities in operating systems and applications
- Regulatory Compliance: Built-in compliance dashboards for PCI DSS, HIPAA, GDPR, and other standards
- Cloud Security: Monitors cloud workloads across AWS, Azure, and GCP
- Container Security: Provides security monitoring for Docker and Kubernetes environments
Official Resources
Views: 2