Get in Touch

Course Outline

Establishing Open-Source SIEM Sovereignty

  • Understanding the compliance and cost risks associated with cloud-based SIEMs for log retention.
  • Overview of Wazuh architecture: server, indexer, dashboard, and agents.
  • Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.

Deployment and Architecture Design

  • Implementing single-node and distributed deployment patterns.
  • Utilizing Docker Compose and Kubernetes manifests for deployment.
  • Determining hardware sizing: CPU, RAM, and disk IOPS requirements for log ingestion.
  • Configuring certificates and TLS for secure component communication.

Agent Management Strategies

  • Installing agents via packages, Ansible, or Group Policy Objects (GPO).
  • Managing agent enrollment, key exchange, and group assignments.
  • Implementing agentless monitoring through syslog, AWS S3, or API polling.
  • Executing upgrade strategies for large-scale agent fleets.

Detection Engineering Techniques

  • Developing decoders and rules for log parsing and event extraction.
  • Mapping rule categories to the MITRE ATT&CK framework.
  • Conducting file integrity monitoring (FIM) and rootkit detection.
  • Writing custom rules using XML and YAML syntax.
  • Integrating threat intelligence from MISP, VirusTotal, and AlienVault.

Incident Response and Automation Workflows

  • Executing active responses such as firewall blocking, account disabling, and process termination.
  • Integrating SOAR tools like Shuffle, n8n, or custom webhooks.
  • Correlating alerts to identify multi-stage attack chains.
  • Managing cases and preserving evidence.

Compliance and Reporting Capabilities

  • Mapping controls for PCI-DSS, HIPAA, GDPR, and NIST standards.
  • Monitoring policies related to password strength, encryption, and patching.
  • Generating and exporting scheduled reports.
  • Ensuring audit trail integrity and detecting tampering.

Dashboards and Visualization Tools

  • Customizing Wazuh dashboards and creating widgets.
  • Integrating Grafana for advanced visualization needs.
  • Leveraging Kibana compatibility for legacy Elastic deployments.
  • Designing views for both executive leadership and operational SOC teams.

Maintenance and Scaling Operations

  • Managing indexer shards and implementing hot-warm-cold archiving strategies.
  • Defining log retention policies and executing legal hold procedures.
  • Performing disaster recovery and cluster reconstruction.

Requirements

  • Intermediate knowledge of Linux and Windows system administration.
  • Fundamental understanding of SIEM concepts, including correlation, alerting, and log aggregation.
  • Practical experience with the Elastic Stack or OpenSearch.

Audience Profile

  • Security operations centers seeking to replace commercial SIEM solutions.
  • Compliance teams requiring on-premise log retention capabilities.
  • Government agencies needing sovereign threat detection mechanisms.
 21 Hours

Testimonials (2)

Upcoming Courses

Related Categories