7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

3 alternatives ranked by real activity

Open-source Tenable alternatives

A curated, ranked list of the 3 best open-source alternatives to Tenable.

The best open-source alternative to Tenable is Wazuh. If that doesn't suit you, other good options are DefectDojo and OpenVAS.

Tenable alternatives are mainly security tools. 3 of them shipped code in the last 30 days, 3 can be self-hosted, and 1 uses a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage

DefectDojo

DefectDojo is an open-source vulnerability management and application security posture platform that collects, deduplicates and tracks findings from security scans.

GitHub stars
5k
Last commit
yesterday
Latest release
3.3.300
Licence
BSD-3-Clause
Self-hosted
Yes
Hosted version
Available
defectdojo.comDefectDojo homepage screenshot

DefectDojo is a DevSecOps, application security posture management and vulnerability management tool. It orchestrates end-to-end security testing, tracks vulnerabilities, removes duplicate findings, supports remediation work and produces reports, giving security teams one place to see what scanners across the pipeline have found.

A simple way to try it is uploading sample scan reports, and the project provides Docker Compose instructions for a quick start plus public demo environments for both the commercial Pro edition and the OWASP Community Edition, which reset daily and should not hold sensitive data. Repository topics include vulnerability correlation, security automation and orchestration. It is built with Python and Django and can be deployed on Kubernetes.

The community edition is licensed under BSD-3-Clause and is run on your own infrastructure, while the vendor sells a Pro edition with additional features. It suits AppSec and product security teams consolidating results from many scanners.

Key features

  • Vulnerability tracking and reporting
  • Deduplication of scanner findings
  • Import of security scan reports
  • Remediation workflow management
  • Docker Compose and Kubernetes deployment
  • REST integration into DevSecOps pipelines

Pricing: The open-source Community Edition is free forever. DefectDojo Pro on pay-as-you-go costs $100 per month plus $0.15 per finding processed; pre-paid annual agreements are quoted.

OpenVAS

The scanner component of Greenbone Community Edition, a vulnerability scan engine that runs a continuously updated feed of vulnerability tests.

GitHub stars
4.8k
Last commit
today
Latest release
v23.50.26
Licence
GPL-2.0
Self-hosted
Yes
greenbone.github.ioOpenVAS homepage screenshot

OpenVAS Scanner is the scanning engine of the Greenbone Community Edition and is also used in Greenbone Enterprise appliances. It performs vulnerability scans by running a set of Vulnerability Tests (VTs) that is updated and extended continuously through a feed.

The module is configured, built and installed with CMake and make, and the INSTALL.md file explains how to set up openvas and expose the scanner to other GVM modules. Release files are signed with the Greenbone Community Feed integrity key. Docker images are published to the Greenbone registry, and a fully containerized setup for the Community Edition is also provided.

The repository also contains a Rust project that aims to replace the existing scanner stack made up of openvas-scanner, ospd-openvas and notus-scanner, simplifying scanning by centralizing everything in one place; for now it uses openvas-scanner as the scan engine. The code is licensed under GPL-2.0. Anyone not comfortable building from source is pointed to the Greenbone Enterprise TRIAL virtual machine.

Key features

  • Vulnerability scan engine
  • Continuously updated vulnerability test feed
  • Signed release files
  • Docker images and containerized setup
  • Rust-based replacement scanner stack in progress
  • Integration with other GVM modules

Pricing: Free and open source under the GPL-2.0 licence.

Tenable alternatives: questions

What is the best open-source alternative to Tenable?
Wazuh is the top-ranked open-source alternative to Tenable on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are DefectDojo and OpenVAS.
Are these Tenable alternatives free?
All 3 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 1 also offers a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Tenable alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 3 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all