11/12 free views
Tool
Framework
Security Operations (SecOps)

wazuh

by wazuh

14.5Kstars
2.1Kforks
222watchers
Updated 3 months ago
About

Wazuh is a comprehensive open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Primary Use Case

Wazuh is used by security operations teams, IT administrators, and compliance officers to detect and respond to threats across diverse environments. It helps organizations maintain security posture, identify vulnerabilities, and ensure compliance with regulatory standards by providing centralized monitoring, analysis, and incident response capabilities.

Key Features
  • Intrusion detection (malware, rootkits, suspicious anomalies)
  • Log data analysis and correlation
  • File integrity monitoring
  • Vulnerability detection (CVE correlation)
  • Configuration assessment and compliance checks
  • Incident response capabilities
  • Endpoint and cloud workload protection
  • Integration with Elastic Stack for visualization

Installation

  • Clone the repository: git clone https://github.com/wazuh/wazuh.git
  • Follow the official documentation for detailed installation and setup guides, as it involves multiple components (manager, agents, and potentially Elastic Stack).

Usage

>_ wazuh-control start

Starts the Wazuh manager service.

>_ wazuh-control stop

Stops the Wazuh manager service.

>_ wazuh-control restart

Restarts the Wazuh manager service.

>_ agent_control -l

Lists all connected Wazuh agents.

>_ agent_control -r <agent_id>

Resets the authentication key for a specific agent.

>_ logtest

Tests the Wazuh rules engine with provided log messages.

Security Frameworks
Reconnaissance
Defense Evasion
Discovery
Collection
Response
Usage Insights
  • Integrate Wazuh with Elastic Stack dashboards for enhanced threat hunting and visualization.
  • Leverage Wazuh's file integrity monitoring to detect unauthorized changes during red team exercises.
  • Use Wazuh's vulnerability detection to proactively identify exploitable weaknesses before adversaries do.
  • Automate alerting and incident response workflows by integrating Wazuh with SOAR platforms.
  • Deploy Wazuh agents across cloud and container environments to maintain consistent security visibility.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about wazuh. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team40%
Blue Team90%
Purple Team75%
Details
LicenseOther
LanguageC
Open Issues23083
Topics
security
compliance
log-analysis
vulnerability-detection
cybersecurity
file-integrity-monitoring
infosec
malware-detection
cloud-security
container-security