● Wazuh - Unified XDR & SIEM · Free & open source

Detect, respond, comply.

Wazuh unifies XDR and SIEM in one open-source platform — endpoint detection and response, threat intelligence, file integrity, vulnerability detection and compliance, across endpoints, cloud and containers.

100% free & open source MITRE ATT&CK mapped
WThreat Hunting
live
DashboardEvents
Total
0
Level 12+ alerts
0
Auth failure
0
Auth success
0
Alerts level evolution
MITRE ATT&CK
Password Guessing SSH Brute Force Valid Accounts Account Access
Unified protection

XDR and SIEM, without the licence bill.

One agent, one platform — covering detection, response, integrity, vulnerabilities and compliance across your whole estate.

Threat detection & response

Behavioural and signature analysis with automated active response to contain threats fast.

Log data analysis

Collect, normalise and analyse logs from across your infrastructure in real time.

File integrity monitoring

Detect changes to critical files and registries — a core control for PCI DSS and more.

Vulnerability detection

Correlate installed software against CVE feeds to surface exposure across endpoints.

Cloud & container security

Monitor AWS, Azure, GCP, Docker and Kubernetes for misconfiguration and threats.

Regulatory compliance

Out-of-the-box mapping for PCI DSS, HIPAA, GDPR, NIST 800-53 and TSC.

MITRE ATT&CK

Alerts mapped to ATT&CK tactics and techniques for faster, structured investigation.

Malware detection

Rootcheck, anomaly detection and threat-intel integration to catch malware early.

Free & open source

No per-GB ingest fees — scale detection across thousands of agents at no licence cost.

Why Wazuh

SOC-grade coverage, open economics.

Most SIEM and XDR platforms bill by data volume or endpoint — so teams collect less and see less. Wazuh is free and open source: monitor everything, keep full data sovereignty, and never hit a licence ceiling.

No ingest or endpoint fees

Collect everything — SIEM economics that don't punish you for better visibility.

One agent, full stack

EDR, FIM, vulnerability detection and compliance from a single lightweight agent.

Open source, no lock-in

Read, modify and extend the source code to fit your exact security needs.

Transparency you can audit

Continuously tested and audited by the community — no black box, nothing hidden.

Integrates with your tools

Native hooks to VirusTotal, TheHive, PagerDuty and any third-party API.

Huge community + support

Slack, GitHub, Reddit and Discord — plus optional Wazuh Cloud and professional support.

15M+protected endpoints
100K+enterprise users
30M+downloads per year
How it works

Discover Wazuh, the all-in-one security platform.

An open-source platform that brings SIEM and XDR together in one unified solution — agents on every endpoint, central components that scale from a single node to a clustered, highly-available deployment.

Endpoints
Wazuh agentprevention · detection · response
ServerDesktopLaptopCloud instanceVirtual machine
Wazuh central components
Network load balancerdistributes agent traffic
Wazuh server clustermaster managers · 1…n
Wazuh indexerindexer nodes · 1…n
Wazuh dashboardvisualise · manage
Wazuh users

Wazuh indexer

A highly scalable full-text search and analysis engine that indexes and stores the alerts the server generates — deployed as a single node or a multi-node cluster.

Wazuh server

Manages the agents, analyses the data they send, and runs it through decoders, rules and threat intelligence to find indicators of compromise.

Wazuh dashboard

A flexible web interface for data mining, analysis and visualisation — and for managing Wazuh configuration and monitoring its status.

Agent runs onWindowsmacOSLinuxSolarisHP-UXAIX
Deploy withKubernetesPuppetAnsibleDocker
Wazuh CTI

Vulnerability intelligence, built in.

Wazuh CTI gives you a comprehensive, continuously updated database of CVEs — severity ratings, affected products and mitigation advice — the same intelligence that powers Wazuh's vulnerability detection.

CVSS scoring & severity

Filter by score, severity and date to focus on what matters most.

Always current

New CVEs, ratings and mitigation advice added continuously from multiple sources.

Feeds detection

Correlated against the software installed on every Wazuh agent.

Vulnerability Explorer
cti.wazuh.com
355,182CVEs
181,910Products
12.3MAffected
CVE-2026-3187OpenSSL heap buffer overflowCRITICAL
CVE-2026-2944Apache HTTP request smugglingHIGH
CVE-2026-2710Microsoft Windows LPEHIGH
CVE-2026-2588PostgreSQL authentication bypassMEDIUM
Cloud posture

Find the misconfiguration before attackers do.

Wazuh continuously assesses the security posture of your AWS, Azure and GCP accounts — flagging risky IAM, exposed services and policy drift against CIS benchmarks, all in one console.

Continuous configuration assessment

CIS-benchmarked checks run across cloud accounts and endpoints, not just once a quarter.

Multi-cloud in one view

AWS, Azure and GCP findings unified and scored by severity on a single dashboard.

Mapped to compliance

Posture findings tie straight back to PCI DSS, HIPAA and NIST controls.

Security Posture Management
cluster: wazuh
Critical High Medium Low
GCPIAM permission exposed to external userHIGH
AzureExposed Kubernetes dashboard detectedHIGH
AWSGuardDuty · unusual outbound from EC2MEDIUM
Use cases by segment

From startups to NASA-scale estates.

Wazuh adapts to the threats, compliance mandates and budgets of every kind of organisation — the same open platform, tuned to each.

Financial services

  • PCI DSS controls out of the box
  • FIM on critical systems
  • Brute-force & fraud detection

Government

  • NIST 800-53 & TSC mapping
  • Self-hosted data sovereignty
  • Vulnerability detection at scale

Healthcare

  • HIPAA controls & audit trails
  • Protect PHI systems
  • Malware & ransomware defence

MSP / MSSP

  • Multi-tenant SOC at scale
  • No per-GB ingest cost
  • 24×7 managed detection

Technology & SaaS

  • Cloud & container security
  • DevSecOps log analysis
  • CVE detection across pipelines

Education

  • Affordable open-source SIEM
  • Broad endpoint coverage
  • Compliance reporting
How it stacks up

Wazuh vs. the alternatives.

Unified, open and no per-GB ingest — compared to the SIEM/XDR platforms teams evaluate most.

Capability WazuhOpen source SplunkES ElasticSecurity CrowdStrikeFalcon
No per-GB / per-endpoint licenceTiered
XDR + SIEM in one platformAdd-onsEDR-led
Built-in compliance mappingPartial
File integrity monitoring (FIM)Add-onAdd-on
Self-hosted, data sovereignty
Vulnerability detection includedAdd-onAdd-on
MITRE ATT&CK mapping

// comparison based on publicly available vendor information; capabilities vary by edition and configuration.

Get Wazuh

Free forever. Supported when you scale.

Run it yourself at no cost, or let Network365 deploy and operate it for you.

Open source

Self-managed

The complete XDR/SIEM platform, free and open — deploy on your own infrastructure.

  • All capabilities, unlimited agents
  • Community support
  • No ingest or endpoint fees
Download free
Most popular
Cloud

Wazuh Cloud

A managed Wazuh deployment with the operational heavy lifting handled for you.

  • Managed, scalable backend
  • Vendor support included
  • Faster time to value
Contact sales
Managed by N365

Managed SOC

Network365 deploys, tunes and monitors Wazuh as a managed detection service.

  • Deployment & rule tuning
  • 24×7 alert triage
  • Compliance reporting
Talk to N365
Why Network365

Your Wazuh partner in Thailand.

Wazuh is free — turning it into reliable, low-noise detection is where a partner pays off. Network365 deploys, tunes and operates Wazuh so you get SOC-grade coverage faster, with local accountability.

Authorized Wazuh partner

Local deployment, support and professional services in Thailand — contracted and billed locally, in THB.

Certified SOC engineers

Specialists deploy Wazuh, write and tune detection rules, and cut false positives down to real signal.

End-to-end delivery

From assessment and architecture to agent rollout, integration, decoders, dashboards and training.

Managed detection (SOC)

24×7 alert triage, threat hunting and incident response — so your team isn't watching consoles all night.

Compliance reporting

PCI DSS, HIPAA, GDPR and NIST 800-53 mapping with audit-ready reports your assessors will accept.

Local support, your timezone

On-site and remote support in Thai and English, with response SLAs that fit your operations.

Assess Deploy Tune Integrate Train Operate
Network365 · Authorized distribution

Build SOC-grade detection without the licence bill.

Talk to Network365 about deploying, tuning and operating Wazuh across your endpoints, cloud and containers.