Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source SIEM
- Examining the compliance and cost risks associated with cloud SIEMs for log retention.
- Overview of Wazuh architecture: server, indexer, dashboard, and agents.
- Benchmarking Wazuh against Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Implementing single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests for orchestration.
- Hardware sizing strategies: CPU, RAM, and disk I/O considerations for log ingestion.
- Configuring certificates and TLS for secure component communication.
Agent Management
- Deploying agents via native packages, Ansible automation, or Group Policy Objects (GPO).
- Managing agent enrollment, key exchange, and group assignments.
- Implementing agentless monitoring through syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large-scale fleets.
Detection Engineering
- Using decoders and rules for effective log parsing and event extraction.
- Mapping rule categories to the MITRE ATT&CK framework.
- Implementing File Integrity Monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence sources such as MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Configuring active response actions: firewall blocking, account disabling, and process termination.
- Integrating SOAR capabilities with Shuffle, n8n, or custom webhooks.
- Correlating alerts to identify multi-stage attack chains.
- Managing cases and ensuring evidence preservation.
Compliance and Reporting
- Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST frameworks.
- Monitoring policies for password strength, encryption standards, and patch management.
- Automating scheduled report generation and export.
- Maintaining audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing the Wazuh dashboard and creating tailored widgets.
- Integrating Grafana for advanced data visualization.
- Maintaining Kibana compatibility for legacy Elastic deployments.
- Developing executive-level and operational SOC views.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold archiving strategies.
- Defining log retention policies and legal hold procedures.
- Executing disaster recovery and cluster rebuild processes.
Requirements
- Intermediate proficiency in Linux and Windows system administration.
- A solid understanding of SIEM concepts, including correlation, alerting, and log aggregation.
- Practical experience with the Elastic Stack or OpenSearch.
Target Audience
- Security Operations Centers (SOCs) looking to transition away from commercial SIEMs.
- Compliance teams requiring on-premise log retention capabilities.
- Government agencies necessitating sovereign threat detection solutions.
21 Hours
Testimonials (1)
The trainer was helpful..