Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Why cloud-based SIEMs may pose compliance and cost risks for log retention.
- Wazuh architecture: components such as the server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests.
- Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
- Certificate and TLS configuration for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or Group Policy Objects (GPO).
- Agent enrollment, key exchange, and group assignment processes.
- Agentless monitoring methods using syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large device fleets.
Detection Engineering
- Decoders and rules for effective log parsing and event extraction.
- Mapping rule categories to MITRE ATT&CK framework.
- File integrity monitoring (FIM) and rootkit detection techniques.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence sources: MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Active response actions: firewall blocking, account disabling, and process termination.
- SOAR integration with tools like Shuffle, n8n, or custom webhooks.
- Alert correlation and tracing multi-stage attack chains.
- Case management workflows and evidence preservation protocols.
Compliance and Reporting
- Mapping controls for PCI-DSS, HIPAA, GDPR, and NIST frameworks.
- Policy monitoring covering password strength, encryption, and patch management.
- Scheduled report generation and data export options.
- Ensuring audit trail integrity and detecting tampering attempts.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating custom widgets.
- Integrating with Grafana for advanced visualization capabilities.
- Maintaining Kibana compatibility for legacy Elastic deployments.
- Designing executive-level and operational SOC views.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold archiving strategies.
- Defining log retention policies and managing legal holds.
- Disaster recovery planning and cluster rebuilding procedures.
Requirements
- Intermediate proficiency in Linux and Windows system administration.
- Familiarity with core SIEM concepts, including correlation, alerting, and log aggregation.
- Practical experience with the Elastic Stack or OpenSearch.
Target Audience
- Security operations centers seeking to replace commercial SIEM solutions.
- Compliance teams requiring on-premise log retention capabilities.
- Government agencies in need of sovereign threat detection infrastructure.
21 Hours
Testimonials (1)
The trainer was helpful..