Monitoring end-of-life software with Wazuh
/ Engineering

Monitoring end-of-life software with Wazuh

Post icon
Detecting common Linux privilege escalation techniques with Wazuh

Detecting common Linux privilege escalation techniques with Wazuh

Post icon
/ Engineering
By

Privilege escalation is the process by which an attacker gains permissions beyond those assigned to their current account. On Linux systems, threat actors who gain initial access as a low-privileged user often exploit misconfigurations or weak security controls to obtain root or other privileged access. With elevated privileges, they can disable security controls, modify system […]

Read more
Real-time threat correlation with Wazuh and OpenCTI

Real-time threat correlation with Wazuh and OpenCTI

Post icon
/ Engineering
By

Modern security operations need deep visibility into endpoints, networks, and cloud workloads, combined with actionable, real‑time intelligence about active threats and adversaries. Without this context, security teams struggle to distinguish high‑priority threats from benign events and low‑value alerts, slowing down investigations and increasing attacker dwell time. Wazuh provides unified visibility and threat detection across your […]

Read more
Defending against the RoguePlanet vulnerability with Wazuh

Defending against the RoguePlanet vulnerability with Wazuh

Post icon
/ Engineering
By

Microsoft Defender is one of the most widely deployed security solutions, shipping out of the box with Windows 10, Windows 11, and Windows Server releases. A newly disclosed zero-day vulnerability, known as RoguePlanet (tracked as CVE-2026-50656), affects how Microsoft Defender handles specific file operations during malware remediation. Successful exploitation can allow an attacker with access […]

Read more
Detecting Stratus Red Team adversary emulation on Microsoft Azure with Wazuh

Detecting Stratus Red Team adversary emulation on Microsoft Azure with Wazuh

Post icon
/ Engineering
By

Microsoft Azure is a cloud computing platform that provides scalable infrastructure, storage, networking, identity management, and security services. Organizations use Azure to host critical workloads, manage enterprise applications, and support hybrid and cloud-native environments. At the core of Microsoft Azure identity infrastructure is Microsoft Entra ID, which manages identities, authentication, and access to cloud resources. […]

Read more
Wazuh and Cloud Carib Join Forces to Enhance SOC Services.

Wazuh and Cloud Carib Join Forces to Enhance SOC Services.

Post icon
/ News
By

San Jose, California, March 2026 – Wazuh, the leading open-source Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) solution, announced a partnership with Cloud Carib, a provider of Sovereign cloud and cybersecurity in the Caribbean and Latin American regions.  Through this strategic partnership, Cloud Carib will implement Wazuh’s unified open-source XDR […]

Read more
Managing shadow IT with Wazuh

Managing shadow IT with Wazuh

Post icon
/ Engineering
By

Shadow IT refers to technology resources, including hardware, software, services, and user accounts, used without the approval or oversight of IT and security teams. This can include remote access tools, cloud storage applications, AI tools, peer-to-peer clients, cryptocurrency miners, unsanctioned SaaS services, cracked software, and other unauthorized technologies. These unauthorized resources create visibility gaps because […]

Read more
Wazuh and The Team Phoenix Partner to Ensure Security Monitoring and Response

Wazuh and The Team Phoenix Partner to Ensure Security Monitoring and Response

Post icon
/ News
By

San Jose, California, June 2026 – Wazuh, the leading open-source Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) solution, announced a partnership with The Team Phoenix Group, a provider of cybersecurity services serving in different sectors in South Asia. Through this partnership, The Team Phoenix  will use Wazuh as the key […]

Read more
Dynamic index routing in Wazuh

Dynamic index routing in Wazuh

Post icon
By

Organizations often collect security events from multiple business units, environments, and infrastructure platforms. As security operations scale, organizations might need to store alerts in different indexes based on their use cases, such as retention policies, access control, and compliance requirements. Dynamic index routing in Wazuh allows administrators to route events to different indices based on […]

Read more
Threat hunting with Agentic AI and Wazuh

Threat hunting with Agentic AI and Wazuh

Post icon
/ Engineering
By

Security Operations Centers face an escalating challenge in managing the high volume of alerts that require manual triage and verification. Each security event requires analysts to identify associated processes, network connections, file modifications, and actions performed in monitored environments. This time-consuming process becomes increasingly unsustainable as log volumes grow, creating correlation bottlenecks that delay incident […]

Read more
Wazuh and Kaydan Drive Africa Digital Transformation

Wazuh and Kaydan Drive Africa Digital Transformation

Post icon
/ News
By

San Jose, California, May 2026 – Wazuh, the leading open-source Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) solution, announced a partnership with Kaydan Technology, an Ivorian company specialized in digital infrastructure, cloud solutions, cybersecurity, data management, and artificial intelligence. This partnership strengthens Kaydan Technology’s ability to provide its clients with […]

Read more
Monitoring MongoDB Atlas with Wazuh

Monitoring MongoDB Atlas with Wazuh

Post icon
/ Engineering
By

MongoDB Atlas is a fully managed, cloud-native database service that provides scalable and flexible document-oriented data storage. Built on the popular MongoDB engine, it enables organizations to deploy, operate, and scale databases across multiple cloud providers with minimal operational overhead. MongoDB Atlas supports high-performance workloads, real-time analytics, and modern application development. It is often used […]

Read more
Optimizing security operations with Wazuh Cloud

Optimizing security operations with Wazuh Cloud

Post icon
/ News
By

Modern organizations rely on SIEM and XDR platforms to improve visibility across their environments and strengthen threat detection and response capabilities. These platforms help security teams collect and analyze security telemetry from across their entire environments, including endpoints, servers, cloud workloads, containers, and network devices. By centralizing this data, security analysts can investigate suspicious activity […]

Read more
Wazuh and AA Teknoloji Partner to Improve Cybersecurity Services

Wazuh and AA Teknoloji Partner to Improve Cybersecurity Services

Post icon
/ News
By

San Jose, California, May 2026 – Wazuh, the leading open source Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) solution, announced a partnership with AA Teknoloji, a tech company that combines the media expertise of Anadolu Ajansı with proprietary in house technologies to deliver innovative solutions in artificial intelligence, media services, […]

Read more
Keep up to date
with our digest of articles