Host-based intrusion detection system comparison
From HandWiki
Comparison of host-based intrusion detection system components and systems.
As per the Unix philosophy a good HIDS is composed of multiple packages each focusing on a specific aspect.
| Package | Last Update | Debian Official Repositories | AlmaLinux Official Repositories | openSUSE Official Repositories | File | Network | Logs | Config | Notes |
|---|---|---|---|---|---|---|---|---|---|
| OSSEC | 2025 | No[1] | No[2] | Yes[3] | Yes | Yes | Yes | Yes | |
| Wazuh | 2025[4] | No | No | ? | Yes | Yes | Yes | Yes | |
| Samhain | 2023 | Yes[5] | No | Yes[6] | Yes | No | Partial[7] | ||
| Snort | 2025[8] | Yes[9] | No[10] | No | No | Yes | No | ||
| chkrootkit | 2023 | Yes[11] | No | Yes | Yes | No | Partial[12] | ||
| rkhunter | 2018 | Yes[13] | Yes[14] | Yes | Yes | No | No | Yes | |
| unhide[15] | 2012 | Yes[16] | Yes[17] | Yes | No | No | No | proc ps compare | |
| Sguil | 2017 | No | No | No | No | Yes | No | ||
| Logwatch[18] | 2017 | Yes[19] | Yes[20] | Yes | No | No | Yes | ||
| Logcheck[21] | 2017 | Yes[22] | Yes[23] | Yes | No | No | Yes | ||
| Epylog[24] | 2014 | Yes[25] | Yes[26] | Yes | No | No | Yes | ||
| SWATCH[27] | 2015 | Yes[28] | Yes[29] | Yes | No | No | Yes | ||
| sagan | 2021 | Yes[30] | No | No | No | No | Yes | ||
| aide | 2025 | Yes[31] | Yes[32] | Yes | Yes | No | No | yes | uses libs for routines |
| tripwire | 2018 | Yes[33] | Yes[34] | Yes | Yes | No | No | ||
| Tiger | 2018 | Yes[35] | No | No | Yes | No | No | Yes | 3/42 modules are Debian specific. |
| Package | Year[36] | Linux | Windows | File | Network | Logs | Config | Notes |
|---|---|---|---|---|---|---|---|---|
| Lacework | 2018 | Yes | No | Yes | Yes | Yes | Yes | |
| Verisys | 2018 | Yes | Yes | Yes | Yes | Yes | ||
| Nessus | 2017 | Yes | Yes | Yes | ||||
| Atomicorp | 2019 | Yes | Yes | Yes | Yes | Yes | Yes | Commercially enhanced version of OSSEC |
| Spartan | 2021 | No | Yes | Yes | Yes | Yes | Yes | Websocket API, IP to Country mapping, DynDNS Integration |
References
- ↑ "Downloads OSSEC". OSSEC. https://ossec.github.io/downloads.html#apt-automated-installation-on-ubuntu-and-debian. Retrieved 2017-10-19. OSSEC for Debian Based systems
- ↑ "Downloads OSSEC". OSSEC. https://ossec.github.io/downloads.html#rhel-centos-fedora-and-others. Retrieved 2017-10-29. OSSEC for RHEL/Fedora Based systems
- ↑ "ossec-hids". openSUSE OBS. https://software.opensuse.org/package/ossec-hids. Retrieved 2024-08-11. An Open Source Host-based Intrusion Detection System
- ↑ "Wazuh documentation Release notes". https://documentation.wazuh.com/current/release-notes/index.html. Retrieved 2025-07-16.
- ↑ "Samhain". Ubuntu. http://packages.ubuntu.com/search?keywords=samhain. Retrieved 2017-04-19. Samhain in the Ubuntu Repositories
- ↑ "Samhain". openSUSE OBS. https://software.opensuse.org/package/samhain?search_term=Samhain. Retrieved 2024-08-11. File integrity and host-based IDS
- ↑ Last
- ↑ "snort3/snort3 Releases". https://github.com/snort3/snort3/releases. Retrieved 2025-07-16.
- ↑ "Snort". Ubuntu. http://packages.ubuntu.com/search?keywords=snort. Retrieved 2017-04-19. Snort in the Ubuntu Repositories
- ↑ "Snort". Cisco Systems. https://pkgs.org/download/snort. Retrieved 2017-05-31. Snort in the CentOS Repositories
- ↑ "ChkRootkit". Ubuntu. http://packages.ubuntu.com/search?keywords=chkrootkit. Retrieved 2017-04-19. ChkRootkit in the Ubuntu Repositories
- ↑ lastlog, wtmp, utmp, wtmpx
- ↑ "RKHunter". Ubuntu. http://packages.ubuntu.com/search?keywords=rkhunter. Retrieved 2017-04-19. RKHunter in the Ubuntu Repositories
- ↑ "RKHunter". Ubuntu. https://pkgs.org/download/rkhunter. Retrieved 2017-04-19. RKHunter in the CentOS Repositories
- ↑ "unhide". debian. https://packages.debian.org/search?keywords=unhide. Retrieved 2017-04-17.unhide is notable because it's part of Debian and Fedora
- ↑ "UnHide". Ubuntu. http://packages.ubuntu.com/search?keywords=unhide. Retrieved 2017-04-19. UnHide in the Ubuntu Repositories
- ↑ "UnHide". Ubuntu. https://pkgs.org/download/unhide. Retrieved 2017-04-19. UnHide in the CentOS Repositories
- ↑ "Logwatch". debian. https://packages.debian.org/search?keywords=logwatch. Retrieved 2017-04-17. Logwatch is notable because it's part of Debian and Fedora
- ↑ "LogWatch". Ubuntu. http://packages.ubuntu.com/search?keywords=logwatch. Retrieved 2017-04-19. LogWatch in the Ubuntu Repositories
- ↑ "LogWatch". Ubuntu. https://pkgs.org/download/logwatch. Retrieved 2017-04-19. LogWatch in the CentOS Repositories
- ↑ "Logcheck". debian. https://packages.debian.org/search?keywords=logcheck. Retrieved 2017-04-17. Logcheck is notable because it's part of Debian and Fedora
- ↑ "Logcheck". Ubuntu. http://packages.ubuntu.com/search?keywords=logcheck. Retrieved 2017-04-19. Logcheck in the Ubuntu Repositories
- ↑ "Logcheck". Ubuntu. https://pkgs.org/download/logcheck. Retrieved 2017-04-19. Logcheck in the CentOS Repositories
- ↑ "Epylog". debian. https://packages.debian.org/search?keywords=epylog. Retrieved 2017-04-17. Epylog is notable because it's part of Debian and Fedora
- ↑ "Epylog". Ubuntu. http://packages.ubuntu.com/search?keywords=epylog. Retrieved 2017-04-19. Epylog in the Ubuntu Repositories
- ↑ "Epylog". Ubuntu. https://pkgs.org/download/epylog. Retrieved 2017-04-19. Epylog in the CentOS Repositories
- ↑ "SWATCH". debian. https://packages.debian.org/search?keywords=swatch. Retrieved 2017-04-17. SWATCH is notable because it's part of Debian and Fedora
- ↑ "SWATCH". Ubuntu. http://packages.ubuntu.com/search?keywords=swatch. Retrieved 2017-04-19. SWATCH in the Ubuntu Repositories
- ↑ "SWATCH". Ubuntu. https://pkgs.org/download/swatch. Retrieved 2017-04-19. SWATCH in the CentOS Repositories
- ↑ "Sagan". Ubuntu. http://packages.ubuntu.com/search?keywords=sagan. Retrieved 2017-04-19. Sagan in the Ubuntu Repositories
- ↑ "AIDE". Ubuntu. http://packages.ubuntu.com/search?keywords=aide. Retrieved 2017-04-19. AIDE in the Ubuntu Repositories
- ↑ "AIDE". Ubuntu. https://pkgs.org/download/aide. Retrieved 2017-04-19. AIDE in the CentOS Repositories
- ↑ "Tripwire". Ubuntu. http://packages.ubuntu.com/search?keywords=tripwire. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
- ↑ "Tripwire". Ubuntu. https://pkgs.org/download/tripwire. Retrieved 2017-04-19. Tripwire in the CentOS Repositories
- ↑ "Tripwire". Ubuntu. http://packages.ubuntu.com/search?keywords=tiger. Retrieved 2017-04-19. Tripwire in the Ubuntu Repositories
- ↑ Last updated
External links
