Wazuh
Wazuh — Open Source Security Platform
Quelloffene Sicherheitsplattform
Wazuh is a widely used open-source security platform that combines functions of Security Information and Event Management (SIEM) and endpoint-based detection (XDR). Via agents it collects events from servers, endpoints and cloud services, evaluates them rule-based and supports, among other things, integrity monitoring, vulnerability detection and compliance evidence. As open source it can be deployed without licence costs.
History & facts. Wazuh emerged from the older open-source project OSSEC and developed into a standalone platform with log analysis, file integrity monitoring, rule-based detection, vulnerability matching and compliance modules. Its open nature allows deep customisation — custom detection rules, decoders and integrations — and full control over one's own data, rather than leaving it to a proprietary cloud service.
Outlook & recommendation. With the Network and Information Security Directive 2 (NIS2) requirement for attack-detection systems, the need for capable, economically viable detection grows — especially in the mid-market. Open source lowers the licence barrier but shifts the cost into operation, tuning and analysis: a platform alone detects nothing if no one works the alerts. The choice of open-source building blocks fits the data-sovereignty stance that NEOSEC (neosec.eu) and its sister company aepfel+birnen represent.