OSSEC
Host-based intrusion detection system
A 20-year-old HIDS is being re-engineered for scale and modern crypto.
◆Recent moves
- 6d ago
Multi-threaded analysisd and a self-contained Windows agent land in 4.2.0
⚡ SPARK4.2.0 makes analysisd multi-threaded by default on Linux servers and migrates manager daemons to pthreads with a shared thread pool. Against the 4.0.0 crypto overhaul, this is the second structural rewrite in six months — the project is systematically removing the architectural limits of its original design.
View source ↗ - 3mo ago
RC1 adds SMTP auth, IPv6 whitelisting, and files over 2GB
A release candidate adding SMTP authentication and TLS to the mail daemon, IPv6 whitelisting improvements, and support for files over 2GB. The changelog is explicitly marked incomplete, and much of the listed work is build and packaging plumbing — CI actions, Rocky Linux 9 support, CentOS 7 fixes.
View source ↗ - 6mo ago
AES becomes the default agent transport in 4.0.0
⚡ SPARK4.0.0 made AES the default for agent-server communication, breaking compatibility with 3.8.0 and older servers, and moved file integrity monitoring to SHA-256. It also closed multiple heap use-after-free bugs and uncontrolled recursion in the XML parser, and replaced insecure agent key generation. This is the release that set the modernization agenda 4.2.0 continues.
View source ↗