Sysmon and wazuh integration with Sigma sysmon rules [updated]
-
Updated
Jul 21, 2021
Sysmon and wazuh integration with Sigma sysmon rules [updated]
Command line tool to review, merge and modify OSSEC/Wazuh rules in bulk
Making Wazuh Deployment Easy
Guide explaining how to deploy the entire Threat Intelligence pipeline inside Wazuh.
An alternative to "wazuh-docker" with CI/CD-built images for amd64 and arm64, published on Docker Hub.
This project simulates real-world PowerShell-based fileless attacks and Living-off-the-Land (LotL) techniques against a Windows 11 endpoint, then detects them using Agent forwarded to a Wazuh SIEM.
In short, just give it access to your alerts.json, default rules, custom rules, archives.json, and magic happens.
This script is for demo purposes only. It deploys a bare minimum, single-node Docker host and Wazuh stack running as a docker-compose stack.
☢️ Python script to send Wazuh alerts to Telegram by bot.
Akamai integration for Wazuh that fetches events using the SIEM API
Setting Up Wazuh SIEM/XDR Homelab and Integration of Microsoft Defender into it.
Docker Container Setup with Wazuh for Vulnerability Scanning DVWA Container
He redactado una guía técnica paso a paso explicando como configurar Wazuh SIEM y automatizar el envío de alertas por correo electrónico ante eventos específicos del sistema usando una integración en Python.
A step-by-step guide to deploying an open-source Wazuh SIEM home lab on an Ubuntu virtual machine, registering a Windows agent, and configuring real-time File Integrity Monitoring (FIM).
Docker image and Helm chart for Wazuh Manager and Filebeat, configurable for sending alerts to a specific OpenSearch instance 🐺
Dieses Projekt zeigt Schritt für Schritt, wie man mit Wazuh, pfSense und Windows 11 ein komplettes SIEM-/XDR-HomeLab aufbaut, Windows-Endpoints per Agent einbindet und typische Monitoring-Szenarien wie File Integrity Monitoring (FIM) und Registry-Überwachung in einer virtuellen Testumgebung umsetzt.
AI-powered Wazuh alert triage and response platform — MITRE ATT&CK insights and automated GitLab incident creation over mTLS
Wazuh, Suricata, IDS, Threat Detection: Integrating Suricata with Wazuh to detect network reconnaissance activity and centralize security monitoring.
Wazuh, Auditd, Threat Hunting | Detecting privileged command execution and endpoint activity through centralized log monitoring.
To associate your repository with the wazuh-manager topic, visit your repo's landing page and select "manage topics."