Get in Touch

Course Outline

Open-Source SIEM Sovereignty

  • Why cloud-based SIEMs may pose compliance and cost risks for log retention.
  • Wazuh architecture: components such as the server, indexer, dashboard, and agents.
  • Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.

Deployment and Architecture

  • Single-node and distributed deployment patterns.
  • Utilizing Docker Compose and Kubernetes manifests.
  • Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
  • Certificate and TLS configuration for secure component communication.

Agent Management

  • Installing agents via packages, Ansible, or Group Policy Objects (GPO).
  • Agent enrollment, key exchange, and group assignment processes.
  • Agentless monitoring methods using syslog, AWS S3, or API polling.
  • Strategies for upgrading agents across large device fleets.

Detection Engineering

  • Decoders and rules for effective log parsing and event extraction.
  • Mapping rule categories to MITRE ATT&CK framework.
  • File integrity monitoring (FIM) and rootkit detection techniques.
  • Writing custom rules using XML and YAML syntax.
  • Integrating threat intelligence sources: MISP, VirusTotal, and AlienVault.

Incident Response and Automation

  • Active response actions: firewall blocking, account disabling, and process termination.
  • SOAR integration with tools like Shuffle, n8n, or custom webhooks.
  • Alert correlation and tracing multi-stage attack chains.
  • Case management workflows and evidence preservation protocols.

Compliance and Reporting

  • Mapping controls for PCI-DSS, HIPAA, GDPR, and NIST frameworks.
  • Policy monitoring covering password strength, encryption, and patch management.
  • Scheduled report generation and data export options.
  • Ensuring audit trail integrity and detecting tampering attempts.

Dashboards and Visualization

  • Customizing Wazuh dashboards and creating custom widgets.
  • Integrating with Grafana for advanced visualization capabilities.
  • Maintaining Kibana compatibility for legacy Elastic deployments.
  • Designing executive-level and operational SOC views.

Maintenance and Scaling

  • Managing indexer shards and implementing hot-warm-cold archiving strategies.
  • Defining log retention policies and managing legal holds.
  • Disaster recovery planning and cluster rebuilding procedures.

Requirements

  • Intermediate proficiency in Linux and Windows system administration.
  • Familiarity with core SIEM concepts, including correlation, alerting, and log aggregation.
  • Practical experience with the Elastic Stack or OpenSearch.

Target Audience

  • Security operations centers seeking to replace commercial SIEM solutions.
  • Compliance teams requiring on-premise log retention capabilities.
  • Government agencies in need of sovereign threat detection infrastructure.
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories