Company Overview
Wazuh originated in 2013 as an open-source fork of OSSEC. Wazuh Inc. was formally founded in 2015 by Santiago Bassett and Alberto Rodelgo, operating with a remote-first model headquartered in the United States and Spain. Wazuh is an open-source unified security monitoring platform offering SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) capabilities.
Wazuh is a CNCF (Cloud Native Computing Foundation) open-source project with an active global community. Its core capabilities include intrusion detection, log analysis, file integrity monitoring (FIM), vulnerability detection, malware detection, and compliance automation (PCI DSS, GDPR, HIPAA, etc.). Built on an Agent-Server architecture, Wazuh can be deployed across physical servers, virtual machines, containers, and cloud environments.
Related provider: Wazuh Security Services
Core Products
| Product | Description |
|---|---|
| Wazuh Manager | Server component responsible for data analysis, alert generation, and policy distribution |
| Wazuh Agent | Endpoint agent deployed on servers and containers for log collection and file change monitoring |
| Wazuh Dashboard | Kibana-based visualization dashboard for security event analysis and reporting |
| Wazuh FIM | File integrity monitoring module for real-time detection of file and registry changes |
| Wazuh Malware Detection | Malware detection module using signature and behavior-based analysis |
| Wazuh Vulnerability Detection | Vulnerability detection module scanning installed software for known vulnerabilities |
| Wazuh Regulatory Compliance | Compliance automation module supporting PCI DSS, GDPR, HIPAA, and other frameworks |
Key Strengths
- Open Source & Free: Licensed under AGPL v3, all features available without commercial licensing
- CNCF Project: Cloud Native Computing Foundation hosted project with an active and rich ecosystem
- Agent-Server Architecture: Supports distributed deployment, managing thousands of endpoints
- Compliance Automation: Built-in compliance report templates for PCI DSS, GDPR, HIPAA, NIST
Milestones
| Year | Event |
|---|---|
| 2013 | Wazuh started as an open-source fork of OSSEC |
| 2015 | Wazuh Inc. formally founded by Santiago Bassett and Alberto Rodelgo |
| 2018 | Joined CNCF as a sandbox project |
| 2026 | Continues leading the open-source SIEM/XDR market with growing global community contributions |
Market Position
Wazuh's main competitors in open-source security monitoring and SIEM/XDR include:
- Elastic Security: SIEM solution based on the Elastic Stack, available in both open-source and commercial versions
- Splunk: Commercial SIEM leader with comprehensive features but higher cost
- OSSEC: Wazuh's predecessor, also an open-source HIDS but with a less active community
- Security Onion: Open-source network security monitoring platform focused on network traffic analysis
- AlienVault (AT&T) / Graylog: Other competitors in the SIEM and log management market