Opensource EDR Agents

Feature / ProjectOpenEDRWHIDSAurora AgentGuardianAIPlanqX EDR
Main FocusEndpoint Detection & Response (EDR)Host Intrusion Detection (HIDS)EDR using Sigma & ETWAI-based AntivirusFull-spectrum EDR
Supported PlatformsWindows
Linux: Planned
macOS: ❌
iOS: ❌
Android: ❌
Windows onlyWindows onlyWindows
Linux: Partial
macOS: ❌
iOS: ❌
Android: ❌
Windows only
Detection MethodTelemetry, File Analysis, LogstashETW + Sysmon + Gene Rule EngineSigma Rules + ETWAI (Neural Nets, Decision Trees, etc.)Kernel Hooks, ETW, AMSI, ELAM, etc.
Extensibility / Custom ModulesPlugin architecture supportedDetection rules and logic are customizableConfigurable rules and actionsCustom AI models can be integratedCustom callbacks, detection modules supported
Ease of Code IntegrationMedium (C/C++ and Elastic integrations)High (modular rule engine)High (rule/config-based)High (Python-based, easy to modify)Medium to High (low-level Windows internals)
Programming Language(s)C++, Elastic Stack integrationsC++, Gene (custom rule engine)GoPythonC, C++, Assembly
UI / ManagementBasic interface + ELK stackCLI, logs-basedCLI / config-basedGUI-basedCLI-based, logs
Data Privacy / Offline CapableRequires network for cloud lookupFully offline capableFully on-premisesFully offline capableFully offline capable
LicenseOpen Source (varied components)GPLGPL-3.0MITGPL-3.0
GitHub LinkOpenEDRWHIDSAurora AgentGuardianAIPlanqX EDR