7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source SentinelOne alternatives

A curated, ranked list of the 4 best open-source alternatives to SentinelOne.

The best open-source alternative to SentinelOne is Wazuh. If that doesn't suit you, other good options are Falco, OSSEC and Security Onion.

SentinelOne alternatives are mainly security tools. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 1 uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage
Read more about WazuhWebsite GitHub

Falco

Cloud native runtime security tool that monitors Linux kernel events and alerts on abnormal behavior and threats in real time.

GitHub stars
9.4k
Last commit
2 days ago
Latest release
0.45.0
Licence
Apache-2.0
Self-hosted
Yes
falco.orgFalco homepage screenshot

Falco is a cloud native runtime security tool for Linux. It detects and alerts on abnormal behavior and potential security threats in real time. At its core it is a kernel monitoring and detection agent that watches events such as system calls and evaluates them against custom rules.

Falco can enrich events with metadata from the container runtime and from Kubernetes, and the collected events can be analyzed off-host in SIEM or data lake systems. The project is split across repositories in the falcosecurity organization: the main repo holds the Falco binary, while others hold the core libraries and kernel drivers, the official ruleset, and plugins that extend detection beyond syscalls and container events.

Falco was originally created by Sysdig and is a graduated project of the Cloud Native Computing Foundation, used in production by various organizations. It is written in C++ and released under the Apache-2.0 license, with a change log and detailed documentation on falco.org. Topics in the repository mention eBPF-based collection.

Key features

  • Kernel-level syscall monitoring
  • Custom detection rules
  • Container and Kubernetes metadata enrichment
  • Official ruleset for common threats
  • Plugins for additional event sources
  • Export to SIEM or data lake systems

Pricing: Free and open source under the Apache-2.0 license.

Read more about FalcoWebsite GitHub

OSSEC

An open-source host-based intrusion detection system that combines log analysis, file integrity checking, rootkit detection, real-time alerting and active response.

GitHub stars
5.1k
Last commit
15 days ago
Latest release
4.3.0
Licence
GPL-2.0
Self-hosted
Yes
ossec.netOSSEC homepage screenshot

OSSEC is a host-based intrusion detection system (HIDS) that watches individual servers and endpoints for signs of compromise. Its README describes it as a platform that brings together HIDS, log monitoring and SIM/SIEM capabilities in one open-source package.

The project's description lists log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. Those capabilities support compliance work as well as detection, and the repository's topics refer to PCI DSS and NIST 800-53. Stable releases and documentation are published on ossec.net, with community help on Slack and Discord.

OSSEC is written in C and licensed under GPL-2.0. It bundles a modified zlib and a small part of OpenSSL, along with the cJSON library. Atomicorp hosts the annual OSSEC conference, and the development version is available through a simple git clone.

Key features

  • Host-based intrusion detection
  • Log analysis and monitoring
  • File integrity monitoring
  • Policy monitoring
  • Rootkit detection
  • Real-time alerting and active response

Pricing: Free and open source under the GPL-2.0 licence.

Read more about OSSECWebsite GitHub

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
today
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections

SentinelOne alternatives: questions

What is the best open-source alternative to SentinelOne?
Wazuh is the top-ranked open-source alternative to SentinelOne on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are Falco, OSSEC and Security Onion.
Are these SentinelOne alternatives free?
All 4 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of SentinelOne alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all