OSSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response.
This new version delivers the most comprehensive update to OSSEC in its history, with numerous new features and bug fixes, including:
- New multi-server architecture
- New platform support for Microsoft Vista (and Server 2008)
- New platform support for VMware ESX
- Added active response module for Windows
- CIS benchmarks on Linux (through the policy auditing)
- Added the VMWare Security hardening guideline to the policy auditing
- Added support for McAfee VirusScan Enterprise logs
- Added support for VMware ESX hostd logs
- Added support for Mac OS FTP server logs
- New tools to better manage the data stored (syscheck_control, rootcheck_control, log_test)
And much more… Check the
changelog to see all changes and contributors.
http://www.ossec.net/main/downloadsDon