← All website monitoring tools
Wazuh
Open-source SIEM/XDR with file-integrity, vuln detection, compliance audit modules — also paid Wazuh Cloud.
Free tier: free open-source self-hosted; paid Wazuh Cloud SaaS starts from agent-priced
What it does well
- Completely free and open-source core platform with a large, active community.
- Extensive compliance reporting modules for PCI DSS, GDPR, HIPAA, and others.
- Highly customizable with broad support for different operating systems and cloud environments.
Where it falls short
- Self-hosted version requires significant technical expertise and ongoing maintenance to manage.
- Can generate a high volume of alerts, requiring careful tuning to reduce noise.
- Wazuh Cloud pricing is based on agents and data retention, which can become costly.
Alternatives to Wazuh
OWASP ZAP
freeMost popular free open-source DAST scanner — active/passive web scanning, intercepting proxy, CI/CD integration.
Tenable Nessus
freemiumIndustry-standard host/network vulnerability scanner — Essentials free for 16 IPs, Pro $3,590/yr.
Greenbone / OpenVAS
freemiumOpen-source vulnerability scanner descended from Nessus — free Community Edition, paid appliances for enterprise.
Template-driven fast scanner — community templates cover thousands of CVEs. Free CLI, paid managed cloud.