Skip to content
OSSEC
Forensics & Incident Response
Open-source host‑based intrusion detection, log monitoring, and SIEM platform
C
·
Latest 4.1.0 · 2mo ago
Security brief →
Features
-
Host‑based intrusion detection (HIDS)
-
Real‑time log monitoring
-
Security Information and Event Management (SIEM) capabilities
Review required
4.1.0
New feature
·
Auth
Dependencies
SMTP TLS + IPv6 + large‑file support + crash fixes
4.0.0
Security relevant
·
Breaking changes
- AES encryption is now default for agent-server communication, breaking compatibility with OSSEC 3.8 and earlier agents.
Security fixes
- Critical UAF bug in memory leak fix (Issue #1818)
- Heap UAF in OSSEC Alert decoder (Issue #1817)
- Uncontrolled recursion in os_xml _ReadElem (Issue #1953)
Notable features
- SHA-256 file integrity monitoring enabled by default for all monitored directories.
- Secure random number generation for agent key generation using OpenSSL RAND_bytes.
- Major dependency updates including Lua 5.4.7, zlib 1.3.1, and cJSON 1.7.18.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
C
·
Shell
·
Perl
View on GitHub
Homepage
Documentation
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open