Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Why cloud-based SIEMs introduce compliance and cost risks regarding log retention.
- Wazuh architecture: server, indexer, dashboard, and agents.
- Comparison with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Single-node and distributed deployment patterns.
- Docker Compose and Kubernetes manifests.
- Hardware sizing: CPU, RAM, and disk IOPS requirements for log ingestion.
- Certificate and TLS configuration for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or Group Policy Objects (GPO).
- Agent enrollment, key exchange, and group assignment.
- Agentless monitoring via syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large fleets.
Detection Engineering
- Decoders and rules for log parsing and event extraction.
- MITRE ATT&CK mapping for categorizing rules.
- File integrity monitoring (FIM) and rootkit detection.
- Creating custom rules using XML and YAML syntax.
- Integrating threat intelligence from sources like MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Active response actions: firewall blocking, account disabling, and process termination.
- SOAR integration with Shuffle, n8n, or custom webhooks.
- Alert correlation and multi-stage attack chaining analysis.
- Case management and evidence preservation techniques.
Compliance and Reporting
- Mapping controls from PCI-DSS, HIPAA, GDPR, and NIST standards.
- Policy monitoring for password strength, encryption standards, and patch management.
- Scheduled report generation and export capabilities.
- Maintaining audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating widgets.
- Grafana integration for advanced visualizations.
- Kibana compatibility for legacy Elastic deployments.
- Tailored views for executive and operational SOC teams.
Maintenance and Scaling
- Indexer shard management and hot-warm-cold data archiving.
- Log retention policies and legal hold procedures.
- Disaster recovery strategies and cluster rebuild processes.
Requirements
- Intermediate-level Linux and Windows system administration skills.
- Understanding of SIEM concepts: correlation, alerting, and log aggregation.
- Experience with the Elastic Stack or OpenSearch.
Audience
- Security operations centers replacing commercial SIEMs.
- Compliance teams requiring on-premise log retention.
- Government agencies needing sovereign threat detection capabilities.
21 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication