Get in Touch

Course Outline

Open-Source SIEM Sovereignty

  • Evaluating the compliance and cost implications of cloud-based SIEMs for log retention requirements.
  • Overview of Wazuh architecture, including server components, indexing engines, dashboards, and agents.
  • Comparative analysis against commercial solutions such as Splunk, Microsoft Sentinel, Elastic Security, and IBM QRadar.

Deployment and Architecture

  • Implementation patterns for single-node and distributed environments.
  • Configuration using Docker Compose and Kubernetes manifests.
  • Hardware specifications: CPU, memory, and disk IOPS requirements for log ingestion.
  • TLS certificate configuration to secure inter-component communications.

Agent Management

  • Agent installation methods: package managers, Ansible, or Group Policy Objects (GPO).
  • Enrollment processes, key exchange mechanisms, and group assignments.
  • Agentless monitoring options via syslog, AWS S3, or API polling.
  • Strategies for upgrading agents across large-scale deployments.

Detection Engineering

  • Decoders and rules for log parsing and event extraction.
  • MITRE ATT&CK framework mapping for rule categorization.
  • File integrity monitoring (FIM) and rootkit detection capabilities.
  • Custom rule development using XML and YAML syntax.
  • Integration with threat intelligence feeds: MISP, VirusTotal, and AlienVault.

Incident Response and Automation

  • Active response actions: firewall blocking, account disabling, and process termination.
  • SOAR integration with platforms such as Shuffle, n8n, or custom webhooks.
  • Alert correlation and multi-stage attack chain identification.
  • Case management procedures and evidence preservation protocols.

Compliance and Reporting

  • Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST standards.
  • Policy monitoring for password complexity, encryption standards, and patch management.
  • Scheduled report generation and export capabilities.
  • Audit trail integrity verification and tamper detection mechanisms.

Dashboards and Visualization

  • Wazuh dashboard customization and widget development.
  • Grafana integration for advanced data visualization.
  • Kibana compatibility for legacy Elastic stack deployments.
  • Visualization views tailored for executive leadership and operational SOC teams.

Maintenance and Scaling

  • Indexer shard management and hot-warm-cold data archiving strategies.
  • Log retention policies and legal hold procedures.
  • Disaster recovery planning and cluster rebuild processes.

Requirements

  • Demonstrated proficiency in intermediate-level administration of Linux and Windows operating systems.
  • Comprehensive knowledge of Security Information and Event Management (SIEM) principles, including log aggregation, alert generation, and data correlation.
  • Practical experience utilizing the Elastic Stack or OpenSearch platforms.

Target Audience

  • Security Operations Centers seeking to transition from commercial SIEM solutions.
  • Compliance divisions requiring on-premise log retention capabilities.
  • Federal and state entities implementing sovereign threat detection frameworks for government operations.
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories