7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Microsoft Defender alternatives

A curated, ranked list of the 5 best open-source alternatives to Microsoft Defender.

The best open-source alternative to Microsoft Defender is Wazuh. If that doesn't suit you, other good options are CrowdSec, OSSEC, Security Onion and ClamAV.

Microsoft Defender alternatives are mainly security tools. 4 of them shipped code in the last 30 days, 5 can be self-hosted, and 1 uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage
Read more about WazuhWebsite GitHub

CrowdSec

CrowdSec is an open-source IDS/IPS, WAF and bot detection engine that blocks malicious IPs using a crowdsourced community blocklist.

GitHub stars
15k
Last commit
today
Latest release
v1.8.1
Licence
MIT
Self-hosted
Yes
docs.crowdsec.netCrowdSec homepage screenshot

CrowdSec is an open-source and participative security solution that detects and blocks malicious behavior on servers. Its Security Engine acts as an all-in-one intrusion detection and prevention system and web application firewall, analyzing log sources and HTTP requests and enforcing decisions through separate remediation components. It runs on Linux, Windows, Docker and Kubernetes.

A Community Blocklist of IP addresses identified as malicious is shared among users, so an address that attacks one participant can be blocked for others before it arrives. Detection and remediation are decoupled, which means logs can be parsed on one machine while blocking happens at a firewall, reverse proxy or CDN elsewhere. A web console supports monitoring and automation.

The README compares it with fail2ban, which reads similar logs, and with ModSecurity, Coraza and naxsi, since the AppSec component is a WAF built on Coraza that loads SecLang rules and the OWASP Core Rule Set. It can also answer suspicious requests with a JavaScript proof-of-work challenge to stop headless scrapers. CrowdSec is written in Go and licensed under MIT.

Key features

  • Log and HTTP request analysis for attack detection
  • Crowdsourced community blocklist of malicious IPs
  • WAF component built on Coraza
  • Remediation at firewall, proxy or CDN
  • Bot detection with proof-of-work challenges
  • Linux, Windows, Docker and Kubernetes support

Pricing: The Security Engine is free and open source under the MIT license.

Read more about CrowdSecWebsite GitHub

OSSEC

An open-source host-based intrusion detection system that combines log analysis, file integrity checking, rootkit detection, real-time alerting and active response.

GitHub stars
5.1k
Last commit
15 days ago
Latest release
4.3.0
Licence
GPL-2.0
Self-hosted
Yes
ossec.netOSSEC homepage screenshot

OSSEC is a host-based intrusion detection system (HIDS) that watches individual servers and endpoints for signs of compromise. Its README describes it as a platform that brings together HIDS, log monitoring and SIM/SIEM capabilities in one open-source package.

The project's description lists log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. Those capabilities support compliance work as well as detection, and the repository's topics refer to PCI DSS and NIST 800-53. Stable releases and documentation are published on ossec.net, with community help on Slack and Discord.

OSSEC is written in C and licensed under GPL-2.0. It bundles a modified zlib and a small part of OpenSSL, along with the cJSON library. Atomicorp hosts the annual OSSEC conference, and the development version is available through a simple git clone.

Key features

  • Host-based intrusion detection
  • Log analysis and monitoring
  • File integrity monitoring
  • Policy monitoring
  • Rootkit detection
  • Real-time alerting and active response

Pricing: Free and open source under the GPL-2.0 licence.

Read more about OSSECWebsite GitHub

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
yesterday
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections
Read more about Security OnionWebsite GitHub

ClamAV

ClamAV is an open-source antivirus engine for detecting trojans, viruses and other malware, maintained by Cisco Talos.

GitHub stars
7.3k
Last commit
1 mo ago
Latest release
clamav-1.5.4
Licence
GPL-2.0
Self-hosted
Yes
clamav.netClamAV homepage screenshot

ClamAV is an open-source antivirus engine that detects trojans, viruses, malware and other malicious threats. It is written in C, released under GPL-2.0 and developed by Cisco Talos. It is used as an engine that other tools and servers can build on, for example scanning files or mail attachments, rather than as a polished desktop product.

Documentation and an FAQ are hosted at docs.clamav.net, and each release archive includes an offline copy. The project explains how to read and write ClamAV signatures through a signature writing manual, so anyone can create detection rules. News, release notes and a blog track new features, and documentation contributions go through a separate repository.

Installation options include official Docker images, distribution package managers, and downloadable installers: Debian and RPM packages for Linux, a universal PKG for macOS and MSI or portable ZIP packages for Windows. It can also be built from source for Unix, Linux, Mac and Windows. Upgrade notes describe moving from earlier versions.

Key features

  • Open-source antivirus scanning engine
  • Detects trojans, viruses and other malware
  • Signature format with a writing manual
  • Docker images and distro packages
  • Installers for Linux, macOS and Windows
  • Offline copy of documentation in each release

Pricing: Free and open source under the GPL-2.0 license.

Read more about ClamAVWebsite GitHub

Microsoft Defender alternatives: questions

What is the best open-source alternative to Microsoft Defender?
Wazuh is the top-ranked open-source alternative to Microsoft Defender on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are CrowdSec, OSSEC, Security Onion and ClamAV.
Are these Microsoft Defender alternatives free?
All 5 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of Microsoft Defender alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all