Ossec & Ossim Unified Open Source Security Online

The "unified" approach relies on the specific strengths of each tool working in tandem:

Open Source Security Information Management by AlienVault (now AT&T Cybersecurity). It acts as a SIEM (Security Information and Event Management) platform that: OSSEC & OSSIM Unified Open Source Security

Detecting unauthorized changes to critical system files. Rootkit Detection: Identifying hidden malicious software. The "unified" approach relies on the specific strengths

Connects seemingly unrelated events from different sources to identify complex attack patterns. OSSEC & OSSIM Unified Open Source Security

Collects events from OSSEC agents and other network tools (like Snort or OpenVAS).