Comparison

Microsoft Sentinel vs Wazuh

On the evidence we track, Wazuh leads this comparison with a composite score of 43/100. Scores are only directly comparable because these tools share a category; the full breakdown and every source is below.

Machine formatsJSONMarkdownGraphQLor send Accept: application/json
Microsoft Sentinel34
Wazuh43
Score
Vioscale score
Microsoft Sentinel34 / 100medium · 64%
Wazuh43 / 100medium · 64%
Pricing
Free tier
Microsoft Sentinel
Wazuh
Model
Microsoft Sentinelcommercial
Price level
Microsoft Sentinelunknown
Wazuhfree
Transparent
Microsoft Sentinel
Wazuh
Integrations
Count
Microsoft Sentinel
Wazuh3
Security
Gdpr
Microsoft Sentinel
Wazuh
Iso27001
Microsoft Sentinel
Wazuh
Pci
Microsoft Sentinel
Wazuh
Scorecard
Microsoft Sentinel
Wazuh4.9
Reliability
Status page
Microsoft Sentinel
Wazuh
Adoption
Dependent repos
Microsoft Sentinel
Wazuh0
Github stars
Microsoft Sentinel
Wazuh16,689
Activity
Commits last 30d
Microsoft Sentinel
Wazuh100
Release
Cadence days
Microsoft Sentinel
Wazuh27
History
Microsoft Sentinel
Language
Primary
Microsoft Sentinel
WazuhC++
Market

Capabilities

Feature-by-feature on the axes that matter for siem & soar software. “-” means undocumented, not absent.

Core
SIEM (log correlation & detection)
Microsoft Sentinel
Wazuh
SOAR (playbooks / automated response)
Microsoft Sentinel-
Wazuh
Detection
UEBA (behavioural analytics)
Microsoft Sentinel-
Wazuh-
Built-in threat intelligence
Microsoft Sentinel-
Wazuh
ML / anomaly detection
Microsoft Sentinel
Wazuh-
MITRE ATT&CK detection mapping
Microsoft Sentinel-
Wazuh
Ops
Case / incident management
Microsoft Sentinel
Wazuh
Pricing
Pricing basis
Microsoft Sentinel-
Wazuh-
Deployment
Deployment
Microsoft SentinelCloud
WazuhHybrid
Integration
Connector / content-pack breadth
Microsoft Sentinel-
WazuhCloud and endpoint integrations including AWS services and threat intelligence f
Licensing
Open-core available
Microsoft Sentinel-
Wazuh

What each one is

The product in its own terms, so the numbers below have context.

Microsoft Sentinel

Microsoft Sentinel is a cloud-hosted security monitoring platform that uses artificial intelligence to detect threats across an organization's infrastructure and support incident investigation and response.

Independently observed

Wazuh

Leader

Unified XDR and SIEM platform that analyzes security data across endpoints, clouds, and networks to detect threats, respond to incidents, and ensure compliance.

Independently observed

Pricing

List pricing as published by each vendor, with the date we read it. Always verify at the source before you buy.

Microsoft Sentinel

as of verify ↗

Wazuh

Leader
Open sourceFree tier
as of verify ↗

Platform & deployment

Where each product runs and how it can be hosted. A dash means undocumented, not unsupported.

Platforms
Web
Microsoft Sentinel
Wazuh
macOS
Microsoft Sentinel
Wazuh
Windows
Microsoft Sentinel
Wazuh
Linux
Microsoft Sentinel
Wazuh
CLI
Microsoft Sentinel
Wazuh
Deployment
Cloud / SaaS
Microsoft Sentinel
Wazuh
Self-hosted
Microsoft Sentinel
Wazuh
On-premise
Microsoft Sentinel
Wazuh
Hybrid
Microsoft Sentinel
Wazuh

Integrations

What each product connects to. Counts come from the vendor's own integration directory where one exists.

Microsoft Sentinel

Not documented yet.

Wazuh

Leader
3 total
  • Amazon Security Lake
  • AWS Inspector
  • AWS SQS
Independently observed

Comparison generated from independently-sourced facts. Every value links to its source and retrieval date. See the method.