7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

3 alternatives ranked by real activity

Open-source Trellix alternatives

A curated, ranked list of the 3 best open-source alternatives to Trellix.

The best open-source alternative to Trellix is Wazuh. If that doesn't suit you, other good options are OSSEC and Security Onion.

Trellix alternatives are mainly security tools. 3 of them shipped code in the last 30 days, 3 can be self-hosted, and none uses a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

Wazuh

Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads.

GitHub stars
17k
Last commit
today
Latest release
v4.14.8
Self-hosted
Yes
wazuh.comWazuh homepage screenshot

Wazuh is a free and open-source platform for threat prevention, detection and response. It protects workloads across on-premises, virtualized, containerized and cloud environments and combines XDR and SIEM functions in one product. The code is written mainly in C++.

The solution consists of an endpoint security agent installed on monitored systems and a management server that collects and analyzes the agents' data. It is integrated with the Wazuh Indexer, which offers a search engine and visualization for navigating security alerts. Agents scan for malware, rootkits and suspicious anomalies, read system and application logs, and monitor files for changes to content, permissions, ownership and attributes.

Rule-based analysis of collected logs, including data received from network devices through syslog, helps surface misconfigurations, policy violations and attempted or successful attacks. Repository topics also cover vulnerability detection, configuration assessment, incident response and compliance such as PCI DSS. The repository lists its license as 'Other', so review the license files for the exact terms.

Key features

  • Endpoint agents with a central management server
  • Intrusion and malware detection
  • Log data analysis with rule-based alerts
  • File integrity monitoring
  • Vulnerability detection and configuration assessment
  • Cloud and container workload coverage

OSSEC

An open-source host-based intrusion detection system that combines log analysis, file integrity checking, rootkit detection, real-time alerting and active response.

GitHub stars
5.1k
Last commit
16 days ago
Latest release
4.3.0
Licence
GPL-2.0
Self-hosted
Yes
ossec.netOSSEC homepage screenshot

OSSEC is a host-based intrusion detection system (HIDS) that watches individual servers and endpoints for signs of compromise. Its README describes it as a platform that brings together HIDS, log monitoring and SIM/SIEM capabilities in one open-source package.

The project's description lists log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. Those capabilities support compliance work as well as detection, and the repository's topics refer to PCI DSS and NIST 800-53. Stable releases and documentation are published on ossec.net, with community help on Slack and Discord.

OSSEC is written in C and licensed under GPL-2.0. It bundles a modified zlib and a small part of OpenSSL, along with the cJSON library. Atomicorp hosts the annual OSSEC conference, and the development version is available through a simple git clone.

Key features

  • Host-based intrusion detection
  • Log analysis and monitoring
  • File integrity monitoring
  • Policy monitoring
  • Rootkit detection
  • Real-time alerting and active response

Pricing: Free and open source under the GPL-2.0 licence.

Security Onion

Security Onion is a free Linux platform for threat hunting, network and host security monitoring and log management, with a unified web console.

GitHub stars
4.9k
Last commit
yesterday
Latest release
3.3.0-20260911
Self-hosted
Yes
securityonion.netSecurity Onion homepage screenshot

Security Onion is a no-cost, open Linux distribution built for threat hunting, security monitoring across an enterprise, and log management. It bundles a suite of tools designed to work together so defenders get visibility into both network and host activity from a single platform.

The Security Onion Console is a unified web interface for analyzing events and managing the deployment, with its own tools for alerting, dashboards, hunting, packet capture, detections and case management. Underneath it uses the Elastic Stack for search, Suricata for network intrusion detection, Elastic Fleet for host monitoring, Zeek for network metadata and other tools such as osquery and CyberChef. The installer and configuration are largely shell scripts.

The repository license appears as 'Other' on GitHub. Security Onion is deployed on your own hardware or virtual machines, either standalone or as a distributed grid. It suits security operations centers, incident responders and blue teams that want an integrated, open alternative to commercial monitoring platforms.

Key features

  • Unified Security Onion Console web interface
  • Network intrusion detection with Suricata
  • Network metadata from Zeek
  • Elastic Stack search and dashboards
  • Case management and threat hunting
  • Packet capture and detections

Trellix alternatives: questions

What is the best open-source alternative to Trellix?
Wazuh is the top-ranked open-source alternative to Trellix on Enlisted: Wazuh is a free, open-source security platform combining XDR and SIEM capabilities for endpoints, servers and cloud workloads. Other strong options are OSSEC and Security Onion.
Are these Trellix alternatives free?
All 3 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of Trellix alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 3 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all