Detection and monitoring Institution-led

OpenWEC

Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent.

By CEA IT Security · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CEA IT Security
Recorded country
France
Product model
Open source
Deployment
Self-hosted / Desktop/CLI
Software license
GPL-3.0-or-later
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

Published and maintained by CEA IT Security within the French national commission.

Reported capabilities

  • Receives Windows event logs using the built-in Windows Event Forwarding protocol.
  • Runs a Linux server with a CLI for subscription management.
  • Supports source-initiated push mode.

Scope and limits

Log collection infrastructure, not a detector or SIEM by itself; source-initiated push is the only WEF mode documented as supported.

Inspect the research evidence 2 source observations
  1. identity / capabilities / deployment / license

    README describes a GPLv3-or-later Linux WEC server and management CLI, agentless Windows collection, and the source-initiated push limitation.

    Read source
  2. origin / country / maintenance

    CEA IT Security identifies its French commission affiliation and lists OpenWEC with September 2026 repository activity.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection