Detection and monitoring Institution-led
OpenWEC
Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent.
By CEA IT Security · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- CEA IT Security
- Recorded country
- France
- Product model
- Open source
- Deployment
- Self-hosted / Desktop/CLI
- Software license
- GPL-3.0-or-later
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin notePublished and maintained by CEA IT Security within the French national commission.
Reported capabilities
- Receives Windows event logs using the built-in Windows Event Forwarding protocol.
- Runs a Linux server with a CLI for subscription management.
- Supports source-initiated push mode.
Scope and limits
Log collection infrastructure, not a detector or SIEM by itself; source-initiated push is the only WEF mode documented as supported.
Inspect the research evidence 2 source observations
identity / capabilities / deployment / license
README describes a GPLv3-or-later Linux WEC server and management CLI, agentless Windows collection, and the source-initiated push limitation.
Read sourceorigin / country / maintenance
CEA IT Security identifies its French commission affiliation and lists OpenWEC with September 2026 repository activity.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection