Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding how cloud SIEMs introduce compliance and cost risks for log retention.
- Overview of Wazuh architecture: server, indexer, dashboard, and agents.
- Comparison with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Single-node and distributed deployment patterns.
- Docker Compose and Kubernetes manifests configuration.
- Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
- Certificate and TLS setup for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or GPO.
- Managing agent enrollment, key exchange, and group assignment.
- Implementing agentless monitoring via syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large fleets.
Detection Engineering
- Creating decoders and rules for log parsing and event extraction.
- Mapping rule categories to the MITRE ATT&CK framework.
- Implementing file integrity monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence sources such as MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Executing active responses: firewall blocking, account disabling, and process termination.
- Integrating with SOAR tools like Shuffle, n8n, or custom webhooks.
- Correlating alerts and analyzing multi-stage attack chains.
- Managing cases and preserving evidence.
Compliance and Reporting
- Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST standards.
- Monitoring policies for password strength, encryption, and patch management.
- Generating and exporting scheduled reports.
- Ensuring audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating widgets.
- Integrating with Grafana for advanced visualizations.
- Utilizing Kibana compatibility for legacy Elastic deployments.
- Designing executive and operational SOC views.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold archiving.
- Defining log retention policies and legal hold procedures.
- Executing disaster recovery and cluster rebuilds.
Requirements
- Intermediate-level system administration skills for Linux and Windows.
- Familiarity with SIEM concepts: correlation, alerting, and log aggregation.
- Experience working with the Elastic Stack or OpenSearch.
Audience
- SOC teams transitioning from commercial SIEMs.
- Compliance teams requiring on-premise log retention.
- Government agencies needing sovereign threat detection capabilities.
21 Hours
Testimonials (1)
The trainer was helpful..