About OSSEC
OSSEC is a host-based intrusion detection system (HIDS) that watches individual servers and endpoints for signs of compromise. Its README describes it as a platform that brings together HIDS, log monitoring and SIM/SIEM capabilities in one open-source package.
The project's description lists log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. Those capabilities support compliance work as well as detection, and the repository's topics refer to PCI DSS and NIST 800-53. Stable releases and documentation are published on ossec.net, with community help on Slack and Discord.
OSSEC is written in C and licensed under GPL-2.0. It bundles a modified zlib and a small part of OpenSSL, along with the cJSON library. Atomicorp hosts the annual OSSEC conference, and the development version is available through a simple git clone.
Key features
- Host-based intrusion detection
- Log analysis and monitoring
- File integrity monitoring
- Policy monitoring
- Rootkit detection
- Real-time alerting and active response
Good fit for
- →Monitoring servers for tampering
- →Supporting compliance-driven file integrity monitoring
- Built with
- C
- Tags
- hids
- intrusion-detection
- security
- file-integrity
- log-analysis
- siem
- compliance
- rootkit-detection
OSSEC: questions and answers
- What is OSSEC used for?
- OSSEC is an open-source host-based intrusion detection system that combines log analysis, file integrity checking, rootkit detection, real-time alerting and active response. It is a good fit for monitoring servers for tampering and supporting compliance-driven file integrity monitoring.
- Is OSSEC open source?
- Yes. OSSEC is open source under the GPL-2.0 licence. Its source code is on GitHub at ossec/ossec-hids and is written mainly in C.
- Is OSSEC free?
- Yes. OSSEC is open source, so the software itself is free to use.
- Can I self-host OSSEC?
- Yes. OSSEC can be self-hosted on your own server or infrastructure.
- What is OSSEC an alternative to?
- OSSEC is an open-source alternative to CrowdStrike, SentinelOne, Microsoft Defender and Kaspersky. Other open-source alternatives to CrowdStrike include Wazuh, Security Onion and Falco.
- Is OSSEC actively maintained?
- Yes. The most recent commit to OSSEC was on 17 September 2026, and the latest release is 4.3.0, published on 25 August 2026. The project has 5.1k stars on GitHub.
Open-source alternatives to OSSEC
See all
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
ClamAV
Security
ClamAV - Documentation is here: https://docs.clamav.net
GPL-2.0vs Avast★ 7.3k
Security Onion
Security
Security Onion is a free and open platform for threat hunting, enterprise security monitor
OSSvs Splunk★ 4.9k
Falco
Security
Cloud Native Runtime Security
Apache-2.0vs Wiz★ 9.4k
CrowdSec
Security
Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with
MITvs Cloudflare★ 15k
OPNsense
Security
OPNsense GUI, API and systems backend
BSD-2-Clausevs Fortinet★ 4.7k
SaaS alternatives to OSSEC
See all
CrowdStrike
Security
Cloud-native endpoint protection, threat detection and response platform
SaaS
SentinelOne
Security
AI-driven endpoint, cloud and identity security platform with automated response
SaaS
Microsoft Defender
Security
Microsoft endpoint, identity and cloud threat protection suite
SaaSKaspersky
Security
Antivirus, VPN and endpoint security products for home and business users
SaaS
ESET
Security
Antivirus and endpoint detection products from a Slovak security vendor
SaaS
Sophos
Security
Endpoint, firewall and managed detection and response services for businesses
SaaS

