Vigilance vs Wazuh

Updated 5 Oct 2026

Wazuh watches machines and logs and tells you when a file changed. Vigilance finds the update that gained a hidden power, before you install it.

Start Free See Pricing

The Catch Wazuh Cannot Make

A file integrity module reports that a file differs from its baseline. It does not read the new file and say what it can do. Vigilance reads the change itself. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

A real one: xz Utils, 2024

xz is a compression library on almost every Linux server. In release 5.6.1, a hidden backdoor shipped inside liblzma. It can intercept a remote login. The release was signed by its own maintainer. A baseline check sees only that the library changed, and every normal update changes it too. One command shows what the change can do:

vigi diff --old ./xz-5.4.6 --new ./xz-5.6.1

HEADS UP. 1 file changed. liblzma can now run hidden code during a remote login.

Read the record: xz Utils backdoor. See more in the attack library.

Run both. Wazuh watches the fleet over time and matches installed software to known bugs. Vigilance checks each update before you trust it. The two sit side by side below. For the wider field, read the software supply chain security tools guide or the full list of comparisons.

What Wazuh Does Well

Wazuh gives a security team one open source platform for endpoint monitoring, log analysis and compliance reporting. Its own site calls it an open source platform that unifies XDR and SIEM. Wazuh lists these abilities on its platform page: malware detection, incident response, file integrity monitoring, threat hunting mapped to MITRE ATT&CK, vulnerability detection, configuration assessment and compliance reports.

The design has four parts. Agents run on the endpoints. The Wazuh server analyzes the data that agents send, using decoders and rules, and it can scale out as a cluster. The indexer stores and searches the alerts. The dashboard shows them. The documentation lists agents for Linux, Windows, macOS, Solaris, AIX and HP-UX. That list is wide, and it includes systems that few modern tools cover.

Wazuh also reaches devices that cannot run an agent. The documentation says it can monitor firewalls, switches, routers and network intrusion detection systems through syslog, SSH or an API.

The file integrity module is strong for its job. The syscheck module runs a baseline scan and stores the checksum and other attributes of each monitored file. It alerts on a mismatch. It supports real-time monitoring and scheduled scans. Who-data monitoring records which user or process changed a file. On Windows, the module also monitors registry changes. For a regulated company that must show an auditor that files stayed the same, this is the right class of tool. See file integrity monitoring for the category.

The vulnerability module uses the software inventory that each agent sends. It matches that list against vulnerability intelligence. The documentation names two sources, the Wazuh CTI platform in the cloud and an offline repository that you host. Dashboards cover PCI DSS, GDPR, CIS, HIPAA and NIST 800-53.

The cost is the last strength. The software is open source. Wazuh sells support, consulting, training and a managed cloud option, so a team can start with no license fee.

Where It Falls Short

Wazuh falls short on one question: what the new file can do that the old file cannot do. The pages we read describe a baseline check and a match against known vulnerabilities. They do not describe a comparison of two versions of a package for new capabilities.

This matters for updates. A baseline records a file as it was. After an update, many files differ from that baseline, and a backdoored update produces the same kind of alert as a clean one. The analyst must still open the file and decide. Wazuh does not remove that work. Vigilance reads the file and reports only the ones that gained a capability, such as reaching the internet or reading your keys.

The vulnerability module has a similar limit. It matches installed software to known vulnerabilities. A new attack in a package that no report covers yet has no match to find. Vigilance keeps no list. It needs no feed to see that a file gained a power.

The second gap is weight. A full Wazuh deployment needs a server, an indexer and a dashboard, plus an agent on each endpoint. Someone must run, patch and tune those parts. This effort pays off for a security operations team. It is a lot for a person who only wants to check one update. Vigilance is one file. It has no agent, no console and no service.

The third gap is the point in time. Wazuh watches machines that are already running the software. Vigilance can check a package, a container image or an installer before it reaches the machine. It also reads inside deb, rpm, npm, pip, containers, MSI and ISO files.

The fourth gap is the control plane. A large platform means a large system that holds data about every endpoint. Vigilance Pro has no network code in the binary at all. Each machine signs its own receipt into a folder you already back up.

Feature Comparison

The table shows that Wazuh is a platform and Vigilance is a single check. Where the Wazuh documentation is silent, the cell says "Not documented". That does not prove the feature is missing.

Question Wazuh Vigilance
Watches files for change against a baseline Yes. The syscheck module Yes
Tells you what a changed file can now do Not documented Yes
Compares an old version with a new one before you install Not documented Yes
Matches installed software to known vulnerabilities Yes. It correlates the software inventory with a vulnerability source No
Records which user or process changed a file Yes. Who-data monitoring No
Watches the Windows registry Yes No
Collects logs and acts as a SIEM Yes No
Reports on PCI DSS, HIPAA, NIST 800-53 and others Yes. Dashboards No
Agents run on Linux, Windows, macOS, Solaris, AIX and HP-UX One file. Mac, Linux, Windows and the BSDs
Needs a server, indexer and dashboard Yes No. It needs no service
Works with no internet Yes. An offline vulnerability repository exists Yes, on Pro
Open source Yes No

The Wazuh column comes from the Wazuh platform overview, the components page, the file integrity monitoring page and the vulnerability detection page. The Vigilance column comes from our docs and use cases.

When Wazuh Is the Better Fit

Wazuh is the better fit when you need one platform that watches many machines, collects logs and reports on compliance, and you have people to run it.

Choose Wazuh if you run a security operations team. It gives you alerts, threat hunting and a dashboard in one place. Vigilance does not collect logs and has no dashboard for them.

Choose Wazuh if an auditor asks for file integrity monitoring with proof of who changed a file. The who-data feature records the user or process. Vigilance does not track that. The same holds for Windows registry monitoring.

Choose Wazuh if you want an open source license and the freedom to host everything yourself. Vigilance is a commercial product.

Choose Wazuh if you need to match installed software to known vulnerabilities across a fleet. Vigilance is not a vulnerability scanner. It does not list known bugs.

Choose Wazuh if your estate includes Solaris, AIX or HP-UX. Vigilance runs on Windows, Mac, Linux and the BSDs.

Choose Vigilance if your question is about a single update. Use it when a dependency, an image or a vendor installer changes, or when an AI agent installs packages on its own. Read supply chain attack prevention for the practice. A team of one can run it with a single command.

Pricing

The Wazuh software is free and open source. Wazuh charges for services around it, and Wazuh Cloud lists three prices on its site.

The Wazuh Cloud page shows these monthly starting prices. The page does not state a currency.

A 14-day trial with no credit card is on offer. If you host Wazuh yourself, you pay for the servers and the time to run them.

Vigilance has two plans, and both are flat for the whole company. Prices are in Canadian dollars. See the pricing section for the current numbers.

The two products do different jobs, so the prices do not compare one to one. The Wazuh price buys a managed monitoring platform. The Vigilance price buys one check on updates.

Which One Do You Need?

Use both if you run a monitoring platform and you install outside software. Wazuh watches the fleet. Vigilance reads each update before you trust it.

Use Wazuh alone if you need logs, compliance reports and file integrity monitoring in one open source platform. Use Vigilance alone if your need is to vet updates, dependencies and images with no server to run.

Known Risk versus New Risk

Known risk

A file that no longer matches its baseline, or software that matches a known vulnerability. Wazuh works here.

New risk

A file that gained a capability it never had, inside an update that looks normal. Vigilance works here.

Common Questions

Is Vigilance a Wazuh alternative?

Yes, for one job. Wazuh is a large platform that watches machines and logs. Vigilance reads an update and reports each file that gained a new capability. Many teams run both.

What does Vigilance do that Wazuh does not?

Vigilance compares the version you trust with a new one before you install it. It reports each file that can now reach the network, run a command or read a secret. The Wazuh pages we read do not describe that check.

What does Wazuh do that Vigilance does not?

Wazuh collects logs, raises alerts, maps detections to MITRE ATT&CK, assesses configuration, reports on compliance and matches installed software to known vulnerabilities. Vigilance does none of these.

Is Wazuh free?

The Wazuh software is open source and free to use. Wazuh sells support, training and a managed Wazuh Cloud service. Vigilance has a Free plan for up to 50 machines and a Pro plan from $999 per month in Canadian dollars.

Does Wazuh do file integrity monitoring?

Yes. The Wazuh syscheck module stores a baseline of checksums and attributes. It raises an alert when a file no longer matches. It supports real-time and scheduled checks, who-data and Windows registry monitoring.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install. Download Vigilance and start free.

Start Free Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.