Wazuh and Cybolt Announce Partnership Read more: https://ow.ly/TMyQ50ZxEWK #CyberSecurity #OpenSource
Wazuh
Computer and Network Security
Campbell, California 83,143 followers
The Open Source Security Platform. Unified XDR and SIEM protection.
About us
Wazuh is a free and open-source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 10 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com
- Website
-
https://www.wazuh.com
External link for Wazuh
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- Campbell, California
- Type
- Privately Held
- Founded
- 2015
- Specialties
- Log Management, File Integrity Monitoring, Cyber Security, SIEM, XDR, Open Source, Endpoint Detection and Response, Threat Intelligence, Threat Hunting, Incident Response, Vulnerability Detection, Endpoint Protection, Cloud Security, Malware Prevention, and PCI DSS Compliance
Locations
-
Primary
Get directions
1999 S Bascom Ave
Campbell, California 95008, US
Employees at Wazuh
Updates
-
Kubernetes environments constantly evolve through upgrades, configuration changes, and day-to-day administration. Without regular security assessments, configuration drift can introduce weaknesses that go unnoticed. Wazuh Security Configuration Assessment (SCA) helps address this challenge by assessing system configurations against established security baselines and identifying deviations before they become security risks. In our latest blog post, "Scanning Kubernetes infrastructure against CIS Benchmark with Wazuh", we demonstrate how to build a custom Wazuh SCA policy that implements checks from the CIS Kubernetes Benchmark v2.0.1. The policy automatically evaluates a kubeadm-provisioned control-plane node, helping security teams identify misconfigurations and assess their environment against recommended security practices. Read more: https://ow.ly/a8WN50Zx369 #InformationSecurity #CyberSecurity #OpenSource
-
FreeRDP is affected by CVE-2026-64620 (CVSS 9.8 - Critical), a heap-based buffer overflow vulnerability in crypto_rsa_common(). The flaw affects FreeRDP versions before 3.28.0 and occurs when the function writes data to an output buffer before validating the output length. This can result in out-of-bounds writes. On the server side, exploitation can occur before authentication when a client selects RDP Standard Security. An unauthenticated attacker can trigger an overflow, causing a denial-of-service condition. Organizations using FreeRDP should upgrade to version 3.28.0 or later, restrict unnecessary RDP exposure, and monitor for unexpected FreeRDP crashes or suspicious remote access activity. For more information, refer to: https://ow.ly/6cZW50ZwfZT #Vulnerability #Cybersecurity
-
-
Wazuh reposted this
As promised at DevCon26 😎 the whole demo is now yours: https://lnkd.in/dridFMS5 🚩 One command deploys a Wazuh lab on your laptop. A victim server, an attacker box, and three attacks that light up the dashboard: ▶️ SSH brute force ▶️ A rogue admin with passwordless sudo ▶️ A tampered file caught by File Integrity Monitoring. The bit my live demo refused to show you is in there too. A stopwatch from attack, to detection, to the attacker's IP being blocked automatically. There is some AI reporting feature as well for those using self-hosted LLMs. Run it and share your experience with Wazuh. Break it and open an issue. Or tell me what it caught on your box! Finally, Big thank you, to the amazing audience and the Q&A that followed, Loved to see the use of Wazuh in your environment 🧑🚒 . Mauritius Software Craftsmanship Community #Wazuh #MSCC #DevCon26 #DevConMru #Mauritius #OpenSource #CyberSecurity
-
-
-
-
-
+2
-
-
Wazuh reposted this
Over the past few weeks, I've been working on WordPress Security Monitoring with Wazuh SIEM project to improve visibility into WordPress environments using custom telemetry and detection engineering. The objective was simple: move beyond traditional web server logs and provide application-level security monitoring for WordPress. What I built 🔹 Custom WordPress Activity Logging - User authentication monitoring (login, logout, failed logins) - Password reset events - User creation, deletion, and role changes - Profile modifications - Content creation, updates, deletion, trash, and restore events - Plugin activation, deactivation, deletion, and updates - Theme changes - Media uploads with detection of suspicious file extensions - Sensitive WordPress configuration changes - REST API and XML-RPC activity - Administrative page access auditing All events are exported as structured JSON logs for seamless ingestion into Wazuh. 🔹 WordPress Inventory Collection - WordPress core version - Core update availability - Plugin inventory - Theme inventory - Available plugin and theme updates - Auto-update configuration status 🔹 WPScan Integration - WordPress core security status - Vulnerable plugins - Outdated themes - Interesting security findings - CVE information for vulnerable components Wazuh Integration I also developed custom: - Wazuh WP Detection rules - Severity mapping - Correlation rules - JSON-based log parsing The solution detects security events such as: - Failed login attempts and brute-force activity - Privilege escalation - Administrative account changes - Plugin and theme modifications - Vulnerable WordPress components - Outdated plugins and themes - Password reset activity - Suspicious file uploads - Configuration changes - XML-RPC activity - REST API usage This project has been an excellent opportunity to strengthen my skills in SIEM engineering, detection engineering, security monitoring, log management, and WordPress security while building a practical end-to-end monitoring solution. I'm continuing to enhance the project with additional detection logic, richer telemetry, and improved correlation rules to provide deeper visibility into WordPress security events. Feedback and suggestions from the cybersecurity community are always welcome. #CyberSecurity #Wazuh #SIEM #WordPress #DetectionEngineering #BlueTeam #SOC #ThreatDetection #SecurityMonitoring #PHP #Linux #WPScan #IncidentResponse #LogManagement #OpenSource #InformationSecurity #moizuddinrafay #SOCAnalyst #SOCEngineering #SecurityOperations #DetectionRules #DetectionEngineeringLife #ThreatHunting #ThreatDetection #ThreatIntelligence #BlueTeaming #DefensiveSecurity #LogAnalysis #SecurityAnalytics #SIEMEngineer #WazuhSIEM #OpenSourceSecurity #WordPressSecurity #ApplicationSecurity #WebSecurity #CloudSecurity #LinuxSecurity #DigitalForensics #IncidentDetection #IncidentResponse #CyberDefense #SecurityAutomation #JSONLogs #SecurityResearch #CyberThreats
-
-
Reviewing large volumes of security alerts each day makes it hard to spot recurring threats, prioritize incidents, and respond consistently. While continuous monitoring is essential, security teams can also benefit from scheduled summaries that consolidate alert activity and surface the high-severity issues. Our latest blog post, Automating security reporting and response with Wazuh and Shuffle, shows how to generate daily alert reports, escalate incidents based on defined conditions, create cases in TheHive, and deliver summaries to Slack. Read more: https://ow.ly/Ra4y50ZuFuO #InformationSecurity #ThreatHunting #CyberSecurity #OpenSource
-
A big thank you to everyone who joined our recent Wazuh MeetUp, bringing together the cybersecurity community in Colombia 🇨🇴 “Your First SIEM/XDR Choice — Not the Plan B” gave a full perspective about Wazuh and its capabilities. Special thanks to our Ambassador Kevin Muñoz and all attendees for making it possible. We look forward to seeing the community continue to grow 🚀 Check next events here: 🔗 https://lnkd.in/eYVeeGdk
-
-
Wazuh reposted this
🚀 Wazuh SIEM/XDR Series Part 3: Mastering Log Analysis & Custom Rules In Part 2, we covered deployment. Now, let's dive into the core engine that makes Wazuh so powerful: Log Analysis! 🔍 Collecting logs is only the first step. To extract actionable intelligence and detect threats, you need efficient parsing and precise detection rules. In this guide, we break down how Wazuh processes your log data: 1️⃣ The Log Analysis Workflow: From ingesting System, Network, and App logs to real-time analysis, alerting, and visualization on the Wazuh Dashboard. 2️⃣ Decoders: The Key to Log Parsing: Understand how Decoders act as translators, extracting critical fields like Source IPs, Usernames, and Timestamps from raw log data to make it searchable. 3️⃣ Custom Rule Creation & Alerting: Move beyond generic brute-force rules. Learn how to craft Custom Enterprise Rules using: 📈 Fine-tuned Rule Levels (e.g., 10+ for critical events). 🔗 Complex Logic Operators (AND, OR, NOT). ⏱️ Frequency-based Triggers (detecting a pattern over time). 🎯 Field-Specific Pattern Matching (e.g., a specific admin user performing a sensitive action). Key Takeaway: The ability to create custom decoders and rules allows you to tailor Wazuh to your specific environment and identify threats that others might miss. Stay tuned for Part 4: Vulnerability Detection & Remediation! #CyberSecurity #Wazuh #SIEM #XDR #SOC #OpenSource #InfoSec
-
-
Wazuh reposted this
🚀 Wazuh SIEM/XDR Series Part 2: Architecture & Agent Deployment Deploying Wazuh effectively starts with understanding its core components and how agents communicate securely with the manager. In this post, we break down the deployment modes and agent enrollment options for a solid setup! 🧠 Key Architecture Components: ⚙️ Wazuh Manager: Analyzes received data, executes decoders/rules, and triggers active responses. 📊 Wazuh Indexer & Dashboard: Stores, searches, and visualizes security alerts in real-time. 💻 Wazuh Agent: Lightweight service installed on endpoints (Windows, Linux, macOS) for continuous data collection. 🔐 Secure Agent Communication: All communication between endpoints and the manager is protected via AES-encrypted channels using custom keys or auto-enrollment via API. 🛠️ Deployment Options: Manual Installation: Quick & simple for testing or small-scale environments. Automated Configuration Management: Scalable deployment via Ansible, Puppet, or Chef. Cloud & Containerized: Docker containers and Kubernetes sidecars for cloud-native setups. Stay tuned for Part 3: Custom Log Analysis & Rule Creation! #CyberSecurity #Wazuh #SIEM #XDR #SecurityArchitecture #SOC #Linux #OpenSource #InfoSec
-
-
Wazuh reposted this
🚀 Excited to Share My Latest Medium Article! As organizations continue to embrace cloud technologies and automation, building resilient and secure infrastructure has become more important than ever. In my latest article, I explore Self-Healing Infrastructure Security-how AI-driven automation, continuous monitoring, and proactive security controls can help organizations detect threats, respond faster, and improve overall system resilience. I hope this article provides valuable insights for professionals interested in Cybersecurity, DevSecOps, Cloud Security, Infrastructure Security, Wazuh, and Security Automation. #CyberSecurity #DevSecOps #CloudSecurity #InfrastructureSecurity #SecurityAutomation #ThreatDetection #SIEM #CloudComputing #AI #ContinuousLearning #MediumBlog