AEGIS is an open-source cybersecurity defense platform that organizations host themselves to detect, analyze, and respond to threats. Listed detections include SQL injection, XSS, path traversal, command injection, brute force, port scans, credential theft, lateral movement, and C2 beacons. The project describes a five-layer detection pipeline and reports an 11/11 detection score, plus 18-microsecond latency for its middleware layer. Deception features include SSH and HTTP honeypots, breadcrumb credential traps, and attacker interaction profiling. AI features can use OpenRouter, OpenAI, Anthropic, or Ollama; Sigma rules and playbooks are described as working without an AI API key. The free AGPL-3.0 plan is self-hosted with Docker Compose and lists limits of 20 nodes, 100 assets, and 3 users. It is described for individuals, homelabs, and small teams. Enterprise adds unlimited nodes, assets, and users, a compliance dashboard for ISO 27001, NIS2, and SOC 2, SAML or OIDC SSO, an SLA, and dedicated support; its price is custom.
Who it is for
The free plan is described for individuals, homelabs, and small teams able to self-host the platform. Enterprise is aimed at companies seeking broader scale and advanced features.
What is good
- Open-source under the AGPL-3.0 license.
- Sigma rules and playbooks work without an AI API key.
- Includes SSH and HTTP honeypots.
- Free plan lists up to 20 nodes and 100 assets.
- Enterprise lists SAML or OIDC SSO.
What to know first
- Free plan is limited to 3 users.
- Free plan is limited to 20 nodes and 100 assets.
- The platform requires self-hosting.
- Enterprise pricing is custom and not listed.
Freedom251 review
AEGIS: the full review
AEGIS combines threat detection with deception features and can use AI providers or operate its listed rules and playbooks without an AI key. The free plan's node, asset, and user caps and the self-hosted deployment are important constraints to weigh.
AEGIS is an open-source, self-hosted cybersecurity defense platform for detecting, analyzing, and responding to threats. It is best suited to individuals, homelabs, and small teams willing to manage their own deployment. Its blend of threat detection, deception tools, and AI-optional rules is compelling, but the free plan’s small caps and self-hosting requirement narrow its fit.
Overview
AEGIS combines a five-layer detection pipeline with response capabilities that include behavioral detection, automatic isolation, EDR, and rollback or recovery. Its detections span web attacks such as SQL injection and XSS, as well as brute force, port scans, credential theft, lateral movement, and C2 beacons. The project reports an 11/11 detection score and 18-microsecond latency for its middleware layer; those figures do not establish how it will perform in a particular environment.
SSH and HTTP honeypots, breadcrumb credential traps, and attacker interaction profiling add a deception layer for organizations that want to expose suspicious activity around decoy resources. AEGIS is licensed under AGPL-3.0, which makes its open-source status relevant to teams evaluating deployment and licensing obligations.
Key features
Detection and response
The breadth of named detections gives AEGIS a role beyond a narrow ransomware blocker, while automatic isolation and recovery features point toward active response. The exact workflows and recovery behavior are not established, so teams with defined incident-response requirements should validate that these functions meet them before relying on the platform.
AI optional, not AI dependent
AEGIS can use OpenRouter, OpenAI, Anthropic, or Ollama for AI features, and it describes shared threat intelligence. Deterministic Sigma rules and playbooks work without an AI API key, a practical advantage for teams that prefer not to depend on a provider key for those functions. The listed integrations are AI providers; no further integration ecosystem is established.
Self-hosted deployment
The free edition runs on premises and uses Docker Compose: users clone the repository and run docker compose. That gives technically capable teams control over deployment, but it also means AEGIS is not a managed, turnkey service. Linux, macOS, and Windows are among its platform listings, alongside API, web, and self-hosted access.
Pricing
Free · Open Source — 0.00 USD per free
The free plan allows up to 20 nodes, 100 assets, and 3 users. Those limits make it a sensible starting point for an individual, homelab, or small team, but organizations with more assets or users will outgrow it. The plan is self-hosted; there is no free trial because the plan itself is free.
Enterprise — custom pricing
Enterprise removes the node, asset, and user limits and adds an SLA, dedicated support, a compliance dashboard for ISO 27001, NIS2, and SOC 2, and SSO through SAML or OIDC. It is aimed at companies needing scale and advanced controls; teams that do not need those additions may find the free plan’s caps a more decisive constraint than price.
Platforms
AEGIS is listed for API, Linux, macOS, web, Windows, and self-hosted use. Its on-premises deployment model and Docker Compose setup favor teams prepared to operate their own security software rather than buyers seeking a hosted service.
Who it's for
AEGIS is a strong candidate for security-minded individuals, homelabs, and small teams that want broad threat detection and deception features under an open-source license, and are comfortable with self-hosting. Larger companies may consider Enterprise for unlimited scale, SSO, compliance reporting, and support. It is a less suitable choice for teams that need a managed deployment or cannot work within the free tier’s 20-node, 100-asset, and 3-user limits.
Pros and cons
- Pros: Covers a broad range of named threats and combines detection with behavioral monitoring, isolation, EDR, and rollback or recovery.
- Pros: Honeypots and credential traps add deception capabilities, while Sigma rules and playbooks can operate without an AI API key.
- Pros: The free, AGPL-3.0 edition supports self-hosted use and includes up to 20 nodes, 100 assets, and 3 users.
- Cons: Docker Compose self-hosting requires teams to handle deployment themselves.
- Cons: The free plan’s caps can rule it out for growing teams; moving to unlimited scale requires Enterprise custom pricing.
- Cons: The reported detection score and latency do not describe performance in a buyer’s own environment, and the response and recovery workflows are not detailed.
Alternatives
For a wider ransomware protection software directory, compare products by their deployment and endpoint needs. AppCheck is worth considering for individual users who want a free Windows or Linux option, or a paid one- or three-PC plan. ManageEngine Ransomware Protection Plus may suit teams seeking an endpoint-focused option; its free edition covers up to 25 endpoints, and it supports self-hosted, web, and Windows platforms.
NeuShield Ransomware Protection is an alternative for Windows users considering a free edition or a per-device annual license. Kaspersky Anti-Ransomware Tool is a free Windows option. Sangfor EasyConnect has a paid model and broader listed platform coverage, including mobile, desktop, and web. Kaseya Ransomware Protection is a paid option for macOS, web, and Windows, with its detection plan requiring an active VSA subscription and license. Hitachi Universal Volume Manager is a paid API, Linux, self-hosted, and web option that requires a license on the local storage system. Check Point External Risk Management is another paid alternative, listed for Windows, macOS, and Linux.
Verdict
Choose AEGIS if you want open-source, self-hosted threat defense with deception features and rules that do not require an AI key, and your deployment fits within the free plan’s caps. Its main appeal is the breadth of detection and response capabilities in a free, self-managed package. Look elsewhere if you need a managed service, more than 20 nodes, 100 assets, or 3 users without moving to custom-priced Enterprise.
Get started with AEGIS
- Open the AEGIS GitHub repository.
- Clone the repository.
- Run Docker Compose to self-host the free plan.
What the free plan stops at
The free plan covers up to 20 nodes, 100 assets, and 3 users. Enterprise offers unlimited nodes, assets, and users.
Questions about AEGIS
Is AEGIS free?
Yes. The Free · Open Source plan costs 0.00 USD per free and includes up to 20 nodes, 100 assets, and 3 users.
Is AEGIS open source?
Yes. It is offered under the AGPL-3.0 license.
Where can AEGIS run?
Listed platforms include API, Linux, macOS, self-hosted, web, and Windows. Deployment is on premises.
Does AEGIS need an AI API key?
AI features can use OpenRouter, OpenAI, Anthropic, or Ollama. Sigma rules and playbooks work without an AI API key.
What does Enterprise include?
Enterprise includes unlimited nodes, assets, and users, a compliance dashboard for ISO 27001, NIS2, and SOC 2, SAML or OIDC single sign-on, an SLA, and dedicated support. It is billed at a custom price.
AEGIS plans and pricing
All plansCompared on ransomware protection software
- Free plan
- Yes
- Rollback or recovery
- Yes
- Behavioral detection
- Yes
- Automatic isolation
- Yes
- EDR included
- Yes
- Deployment
- on_premises
- Operating system coverage
- cross_platform



