7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

5 alternatives ranked by real activity

Open-source Rapid7 alternatives

A curated, ranked list of the 5 best open-source alternatives to Rapid7.

The best open-source alternative to Rapid7 is Wazuh. If that doesn't suit you, other good options are Graylog, DefectDojo, OpenVAS and Security Onion.

Rapid7 alternatives are mainly security tools, but some are also monitoring & observability tools. 5 of them shipped code in the last 30 days, 5 can be self-hosted, and 1 uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage

Graylog

Graylog is a free, open log management platform written in Java that collects, searches and analyzes logs, with a focus on security use cases.

GitHub stars
8.2k
Last commit
today
Self-hosted
Yes
graylog.orgGraylog homepage screenshot

Graylog is a log management server written in Java and described by its maintainers as free and open. It centralizes log data from many systems so teams can search, view and analyze events in one place instead of connecting to each machine individually.

The repository topics point to support for common log formats and transports, including GELF and syslog, along with Kafka and AMQP inputs. Topics also place the project in log analysis, log collection, secure logging and SIEM territory, which reflects its use for monitoring and security work. Specific features were not available when this entry was written, because the vendor website could not be read.

Key features

  • Centralized log collection and search
  • GELF and syslog input formats
  • Kafka and AMQP integration
  • Log analysis and viewing
  • Security-oriented logging

DefectDojo

DefectDojo is an open-source vulnerability management and application security posture platform that collects, deduplicates and tracks findings from security scans.

GitHub stars
5k
Last commit
yesterday
Latest release
3.3.300
Licence
BSD-3-Clause
Self-hosted
Yes
Hosted version
Available
defectdojo.comDefectDojo homepage screenshot

DefectDojo is a DevSecOps, application security posture management and vulnerability management tool. It orchestrates end-to-end security testing, tracks vulnerabilities, removes duplicate findings, supports remediation work and produces reports, giving security teams one place to see what scanners across the pipeline have found.

A simple way to try it is uploading sample scan reports, and the project provides Docker Compose instructions for a quick start plus public demo environments for both the commercial Pro edition and the OWASP Community Edition, which reset daily and should not hold sensitive data. Repository topics include vulnerability correlation, security automation and orchestration. It is built with Python and Django and can be deployed on Kubernetes.

The community edition is licensed under BSD-3-Clause and is run on your own infrastructure, while the vendor sells a Pro edition with additional features. It suits AppSec and product security teams consolidating results from many scanners.

Key features

  • Vulnerability tracking and reporting
  • Deduplication of scanner findings
  • Import of security scan reports
  • Remediation workflow management
  • Docker Compose and Kubernetes deployment
  • REST integration into DevSecOps pipelines

Pricing: The open-source Community Edition is free forever. DefectDojo Pro on pay-as-you-go costs $100 per month plus $0.15 per finding processed; pre-paid annual agreements are quoted.

OpenVAS

The scanner component of Greenbone Community Edition, a vulnerability scan engine that runs a continuously updated feed of vulnerability tests.

GitHub stars
4.8k
Last commit
today
Latest release
v23.50.26
Licence
GPL-2.0
Self-hosted
Yes
greenbone.github.ioOpenVAS homepage screenshot

OpenVAS Scanner is the scanning engine of the Greenbone Community Edition and is also used in Greenbone Enterprise appliances. It performs vulnerability scans by running a set of Vulnerability Tests (VTs) that is updated and extended continuously through a feed.

The module is configured, built and installed with CMake and make, and the INSTALL.md file explains how to set up openvas and expose the scanner to other GVM modules. Release files are signed with the Greenbone Community Feed integrity key. Docker images are published to the Greenbone registry, and a fully containerized setup for the Community Edition is also provided.

The repository also contains a Rust project that aims to replace the existing scanner stack made up of openvas-scanner, ospd-openvas and notus-scanner, simplifying scanning by centralizing everything in one place; for now it uses openvas-scanner as the scan engine. The code is licensed under GPL-2.0. Anyone not comfortable building from source is pointed to the Greenbone Enterprise TRIAL virtual machine.

Key features

  • Vulnerability scan engine
  • Continuously updated vulnerability test feed
  • Signed release files
  • Docker images and containerized setup
  • Rust-based replacement scanner stack in progress
  • Integration with other GVM modules

Pricing: Free and open source under the GPL-2.0 licence.

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
today
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections

Rapid7 alternatives: questions

What is the best open-source alternative to Rapid7?
Wazuh is the top-ranked open-source alternative to Rapid7 on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are Graylog, DefectDojo, OpenVAS and Security Onion.
Are these Rapid7 alternatives free?
All 5 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Rapid7 alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 5 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all