Get in Touch

Course Outline

Open-Source SIEM Sovereignty

  • Understanding how cloud SIEMs introduce compliance and cost risks for log retention.
  • Overview of Wazuh architecture: server, indexer, dashboard, and agents.
  • Comparison with Splunk, Sentinel, Elastic Security, and QRadar.

Deployment and Architecture

  • Single-node and distributed deployment patterns.
  • Docker Compose and Kubernetes manifests configuration.
  • Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
  • Certificate and TLS setup for secure component communication.

Agent Management

  • Installing agents via packages, Ansible, or GPO.
  • Managing agent enrollment, key exchange, and group assignment.
  • Implementing agentless monitoring via syslog, AWS S3, or API polling.
  • Strategies for upgrading agents across large fleets.

Detection Engineering

  • Creating decoders and rules for log parsing and event extraction.
  • Mapping rule categories to the MITRE ATT&CK framework.
  • Implementing file integrity monitoring (FIM) and rootkit detection.
  • Writing custom rules using XML and YAML syntax.
  • Integrating threat intelligence sources such as MISP, VirusTotal, and AlienVault.

Incident Response and Automation

  • Executing active responses: firewall blocking, account disabling, and process termination.
  • Integrating with SOAR tools like Shuffle, n8n, or custom webhooks.
  • Correlating alerts and analyzing multi-stage attack chains.
  • Managing cases and preserving evidence.

Compliance and Reporting

  • Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST standards.
  • Monitoring policies for password strength, encryption, and patch management.
  • Generating and exporting scheduled reports.
  • Ensuring audit trail integrity and detecting tampering.

Dashboards and Visualization

  • Customizing Wazuh dashboards and creating widgets.
  • Integrating with Grafana for advanced visualizations.
  • Utilizing Kibana compatibility for legacy Elastic deployments.
  • Designing executive and operational SOC views.

Maintenance and Scaling

  • Managing indexer shards and implementing hot-warm-cold archiving.
  • Defining log retention policies and legal hold procedures.
  • Executing disaster recovery and cluster rebuilds.

Requirements

  • Intermediate-level system administration skills for Linux and Windows.
  • Familiarity with SIEM concepts: correlation, alerting, and log aggregation.
  • Experience working with the Elastic Stack or OpenSearch.

Audience

  • SOC teams transitioning from commercial SIEMs.
  • Compliance teams requiring on-premise log retention.
  • Government agencies needing sovereign threat detection capabilities.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories