Get in Touch

Course Outline

Sovereignty in Open-Source SIEM

  • Examining the compliance and cost risks associated with cloud SIEMs for log retention.
  • Overview of Wazuh architecture: server, indexer, dashboard, and agents.
  • Benchmarking Wazuh against Splunk, Sentinel, Elastic Security, and QRadar.

Deployment and Architecture

  • Implementing single-node and distributed deployment patterns.
  • Utilizing Docker Compose and Kubernetes manifests for orchestration.
  • Hardware sizing strategies: CPU, RAM, and disk I/O considerations for log ingestion.
  • Configuring certificates and TLS for secure component communication.

Agent Management

  • Deploying agents via native packages, Ansible automation, or Group Policy Objects (GPO).
  • Managing agent enrollment, key exchange, and group assignments.
  • Implementing agentless monitoring through syslog, AWS S3, or API polling.
  • Strategies for upgrading agents across large-scale fleets.

Detection Engineering

  • Using decoders and rules for effective log parsing and event extraction.
  • Mapping rule categories to the MITRE ATT&CK framework.
  • Implementing File Integrity Monitoring (FIM) and rootkit detection.
  • Writing custom rules using XML and YAML syntax.
  • Integrating threat intelligence sources such as MISP, VirusTotal, and AlienVault.

Incident Response and Automation

  • Configuring active response actions: firewall blocking, account disabling, and process termination.
  • Integrating SOAR capabilities with Shuffle, n8n, or custom webhooks.
  • Correlating alerts to identify multi-stage attack chains.
  • Managing cases and ensuring evidence preservation.

Compliance and Reporting

  • Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST frameworks.
  • Monitoring policies for password strength, encryption standards, and patch management.
  • Automating scheduled report generation and export.
  • Maintaining audit trail integrity and detecting tampering.

Dashboards and Visualization

  • Customizing the Wazuh dashboard and creating tailored widgets.
  • Integrating Grafana for advanced data visualization.
  • Maintaining Kibana compatibility for legacy Elastic deployments.
  • Developing executive-level and operational SOC views.

Maintenance and Scaling

  • Managing indexer shards and implementing hot-warm-cold archiving strategies.
  • Defining log retention policies and legal hold procedures.
  • Executing disaster recovery and cluster rebuild processes.

Requirements

  • Intermediate proficiency in Linux and Windows system administration.
  • A solid understanding of SIEM concepts, including correlation, alerting, and log aggregation.
  • Practical experience with the Elastic Stack or OpenSearch.

Target Audience

  • Security Operations Centers (SOCs) looking to transition away from commercial SIEMs.
  • Compliance teams requiring on-premise log retention capabilities.
  • Government agencies necessitating sovereign threat detection solutions.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories