Comparison of host-based intrusion detection system components and systems.
As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.
Package
|
Year[36]
|
Linux
|
Windows
|
File
|
Network
|
Logs
|
Config
|
Notes
|
Lacework
|
2018
|
Yes
|
No
|
Yes
|
Yes
|
Yes
|
Yes
|
|
Verisys
|
2018
|
Yes
|
Yes
|
Yes
|
Yes
|
|
Yes
|
|
Nessus
|
2017
|
Yes
|
Yes
|
|
|
|
Yes
|
|
Atomicorp
|
2019
|
Yes
|
Yes
|
Yes
|
Yes
|
Yes
|
Yes
|
Commercially enhanced version of OSSEC
|
Spartan
|
2021
|
No
|
Yes
|
Yes
|
Yes
|
Yes
|
Yes
|
Websocket API, IP to Country mapping, DynDNS Integration
|
References
- ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-19. OSSEC for Debian Based systems
- ^ "Downloads OSSEC". OSSEC. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
- ^ "ossec-hids". openSUSE OBS. Retrieved 2024-08-11. An Open Source Host-based Intrusion Detection System
- ^ "Wazuh documentation Release notes". Retrieved 2025-07-16.
- ^ "Samhain". Ubuntu. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
- ^ "Samhain". openSUSE OBS. Retrieved 2024-08-11. File integrity and host-based IDS
- ^ Last
- ^ "snort3/snort3 Releases". Retrieved 2025-07-16.
- ^ "Snort". Ubuntu. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
- ^ "Snort". Cisco Systems. Retrieved 2017-05-31. Snort in the CentOS Repositories
- ^ "ChkRootkit". Ubuntu. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
- ^ lastlog, wtmp, utmp, wtmpx
- ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
- ^ "RKHunter". Ubuntu. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
- ^ "unhide". debian. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
- ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
- ^ "UnHide". Ubuntu. Retrieved 2017-04-19. UnHide in the CentOS Repositories
- ^ "Logwatch". debian. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
- ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
- ^ "LogWatch". Ubuntu. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
- ^ "Logcheck". debian. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
- ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
- ^ "Logcheck". Ubuntu. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
- ^ "Epylog". debian. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
- ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
- ^ "Epylog". Ubuntu. Retrieved 2017-04-19. Epylog in the CentOS Repositories
- ^ "SWATCH". debian. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
- ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
- ^ "SWATCH". Ubuntu. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
- ^ "Sagan". Ubuntu. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
- ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
- ^ "AIDE". Ubuntu. Retrieved 2017-04-19. AIDE in the CentOS Repositories
- ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
- ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
- ^ "Tripwire". Ubuntu. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
- ^ Last updated
External links