OSSEC
- Company typePrivate
- Founded2008
- HeadquartersSan Francisco, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
OSSEC firmographics
Firmographics- Name
- OSSEC
- Legal name
- OSSEC Project Team
- Website
- https://ossec.net
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Ownership category
- akta.pro rank
OSSEC industry classification
Industry- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH)
Keywords
Where OSSEC is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
OSSEC business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Revenue model
- OSSEC Open Source: Free open-source Host-based Intrusion Detection System available for download with source code and pre-compiled binaries. No revenue generated from this version.
- OSSEC+ (Free Enhanced Version): Enhanced version of OSSEC available at no cost with registration. Includes additional features such as threat intelligence and hundreds of more rules than basic OSSEC. Revenue model is freemium with registration-based access.
- Atomic OSSEC Enterprise: Commercial-grade enterprise enhancement of OSSEC provided by Atomicorp. Includes enterprise features including centralized endpoint firewall management, vulnerability management, compliance scanning, SIEM, EDR, antivirus, advanced HIDS, machine learning, GUI, and professional support. Priced under $5 per device per month or $55 per agent per year with volume discounts available. Also available as SaaS and white-label XDR solution for MSSPs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | OSSEC (Free Open Source) |
| Freemium | Others | OSSEC+ (Free with Registration) |
| Subscription | Monthly | Atomic OSSEC (Enterprise) |
| Freemium | Pay-as-you-go | Atomic OSSEC SaaS Trial |
Go-to-market motion1 record
Distribution channels7 records
Marketing channels8 records
OSSEC product offering
Product offeringCore offering
OSSEC provides a free, open-source Host-based Intrusion Detection System (HIDS) that performs multi-platform log analysis, file integrity monitoring (FIM), rootkit and malware detection, active response, and compliance auditing. The OSSEC product family spans three tiers: the free open-source OSSEC core, OSSEC+ (free with registration) adding threat intelligence and machine learning, and the commercially licensed Atomic OSSEC enterprise edition (delivered and supported by Atomicorp) that adds 10X the rules, antivirus, EDR, SIEM, vulnerability management, compliance scanning, GUI dashboard (Atomic Inspector), and professional support.
Product overview
OSSEC is an open-source host-based intrusion detection system (HIDS) that provides multi-platform security monitoring, file integrity monitoring, and compliance auditing. The product family includes three tiers: (1) OSSEC — the free open-source core HIDS with log analysis, FIM, malware detection, active response, and compliance auditing; (2) OSSEC+ — a free enhanced version (with registration) that adds machine learning, threat intelligence, hundreds of additional rules, and ELK/OpenSearch integration; and (3) Atomic OSSEC — the commercial enterprise offering from Atomicorp that adds 10X the rules, antivirus, endpoint firewall management, vulnerability scanning, EDR, SIEM, GUI dashboard (Atomic Inspector), and professional support. The OSSEC Virtual Appliance provides a pre-bundled option with ELK stack for log management.
Differentiator
Problem solved
Functional benefit
Brands
- OSSEC+: Enhanced version of OSSEC with additional features including threat intelligence, hundreds of additional rules, ELK integration, community threat sharing, and machine learning. Free with registration.
- Atomic OSSEC
Quantifiable outcome
- 10X the security and compliance rules in Atomic OSSEC compared to free OSSEC
- +2 more outcomes
Companies that use OSSEC
Customer profileNamed customers1 record
Segments5 records
Ideal customer profiles1 record
OSSEC technology and API
TechnologyAPI detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability4 records
Feature8 records
OSSEC partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered minor and core.
- AlienVaultminorAlienVault was a sponsor of OSSEC CON 2014 and has created Debian packages of OSSEC for Ubuntu and Debian distributions (Wheezy, Jessie, Sid) hosted on their repositories. OSSEC Project team member Santiago Gonzalez created these packages with AlienVault hosting.
- AtomicorpcoreAtomicorp is the Platinum Sponsor of OSSEC and actively manages the OSSEC project and develops OSSEC. They provide commercially supported versions (Atomic OSSEC), pre-compiled binaries, and professional support services. Scott R. Shinn from Atomicorp serves as a release maintainer. Atomicorp extends OSSEC with enterprise features including XDR, vulnerability management, compliance scanning, SIEM, EDR, antivirus, and machine learning capabilities.
- Virgil SecurityminorVirgil Security is a Gold Sponsor of OSSEC, supporting the open-source project financially.
- HyperQubeminorHyperQube is a Gold Sponsor of OSSEC, supporting the open-source project financially.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
OSSEC competitors and assessment
Company assessmentBroad incumbents
- Qualys: Qualys provides cloud-based vulnerability management, policy compliance, file integrity monitoring and endpoint security capabilities. It is comparable because Atomic OSSEC includes vulnerability management, compliance scanning and FIM for enterprise security teams.
- Graylog: Graylog offers log management, security analytics and SIEM capabilities. It is comparable because OSSEC’s log-analysis and SIEM integration capabilities serve similar security-operations workflows, particularly for teams centralizing alert and event data.
- Elastic: Elastic provides Elastic Security for SIEM, endpoint security, threat hunting and observability on top of the Elastic Stack. It is comparable because OSSEC integrates into ELK-style workflows and competes for security teams standardizing on log analytics and endpoint telemetry.
- Rapid7: Rapid7 provides InsightIDR, InsightVM and managed detection capabilities covering SIEM, endpoint detection, vulnerability management and compliance workflows. It is comparable to Atomic OSSEC’s commercial bundle of SIEM, EDR, vulnerability detection and compliance scanning.
- Splunk: Splunk provides enterprise log analytics, SIEM and security operations products such as Splunk Enterprise Security. It is comparable because OSSEC generates and forwards security alerts into SIEM environments, competing for budget around detection, investigation and compliance monitoring.
- LevelBlue: LevelBlue, formerly associated with AT&T Cybersecurity and AlienVault assets, offers managed security, threat detection and SIEM-style products such as USM. It is comparable because AlienVault OSSIM/USM historically targeted open security monitoring and SIEM use cases adjacent to OSSEC deployments.
- CrowdStrike: CrowdStrike Falcon is a leading endpoint protection, EDR and XDR platform. It is comparable to Atomic OSSEC’s enterprise positioning around endpoint detection, automated response, antivirus and XDR, though CrowdStrike is a much larger cloud-native incumbent.
Direct peers
- Wazuh: Wazuh is an open-source security platform for XDR/SIEM, endpoint monitoring, file integrity monitoring, vulnerability detection and compliance. It is the closest comparable because it targets many of the same OSSEC HIDS, log-analysis, FIM and compliance use cases, with an open-source-led model.
- Fortra Tripwire: Tripwire provides file integrity monitoring, security configuration management, vulnerability management and compliance solutions. It is comparable because OSSEC’s core value proposition includes real-time FIM, compliance auditing and unauthorized-change detection.
Emerging players
- Security Onion Solutions: Security Onion Solutions develops and supports the open-source Security Onion platform for threat hunting, network security monitoring and log/SIEM workflows. It is comparable as an open-source-led security monitoring platform used by SOC teams, although it is broader and more network/SOC-oriented than OSSEC’s HIDS core.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
OSSEC social profiles
Digital presenceOSSEC compliance and trust
Trust signalCompliance7 records
OSSEC financial estimates
Financial estimateRevenue estimate
Valuation estimate
OSSEC leadership team
Management profileNumber of profiles
OSSEC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OSSEC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OSSEC
What does OSSEC do?
OSSEC provides a free, open-source Host-based Intrusion Detection System (HIDS) that performs multi-platform log analysis, file integrity monitoring (FIM), rootkit and malware detection, active response, and compliance auditing. The OSSEC product family spans three tiers: the free open-source OSSEC core, OSSEC+ (free with registration) adding threat intelligence and machine learning, and the commercially licensed Atomic OSSEC enterprise edition (delivered and supported by Atomicorp) that adds 10X the rules, antivirus, EDR, SIEM, vulnerability management, compliance scanning, GUI dashboard (Atomic Inspector), and professional support.
Is OSSEC a public or private company?
OSSEC is a private company. It is currently operating.
When was OSSEC founded?
OSSEC was founded in 2008. It employs 501 to 1,000 people.
Where is OSSEC based?
OSSEC is headquartered in San Francisco, United States, in the North America region.
How does OSSEC make money?
Three revenue lines are on record. OSSEC Open Source is the primary driver. The others are OSSEC+ (Free Enhanced Version) and atomic OSSEC Enterprise.
Who are OSSEC's main competitors?
Broad incumbents on record are Qualys, Graylog, Elastic, Rapid7, Splunk, LevelBlue and CrowdStrike. Direct peers are Wazuh and Fortra Tripwire. Security Onion Solutions is listed as an emerging player.
Does OSSEC have an API?
No public API is recorded for OSSEC.
What industry is OSSEC in?
Its primary akta.pro industry code is HDADABAH, Intrusion Prevention/Detection Systems (IPS/IDS). Its NAICS code is 5415 and its SIC code is 7371.