Get in Touch

Course Outline

Open-Source SIEM Sovereignty for Government

  • Analysis of compliance liabilities and cost structures associated with cloud-based SIEM log retention.
  • Examination of Wazuh architecture: server, indexer, dashboard, and agents.
  • Evaluation against Splunk, Sentinel, Elastic Security, and QRadar.

Deployment and Architecture

  • Single-node and distributed deployment patterns.
  • Utilization of Docker Compose and Kubernetes manifests.
  • Hardware sizing: CPU, RAM, and disk IOPS requirements for log ingestion.
  • Certificate and TLS configuration for secure component communication.

Agent Management

  • Deploying agents via packages, Ansible, or Group Policy Objects.
  • Agent enrollment, key exchange, and group assignment processes.
  • Agentless monitoring via syslog, AWS S3, or API polling methods.
  • Strategies for upgrading agents across large enterprise fleets.

Detection Engineering

  • Decoders and rules for log parsing and event extraction.
  • Mapping rules to MITRE ATT&CK categories.
  • File integrity monitoring (FIM) and rootkit detection capabilities.
  • Developing custom rules using XML and YAML syntax.
  • Integrating threat intelligence from MISP, VirusTotal, and AlienVault.

Incident Response and Automation

  • Active response mechanisms: firewall blocking, account disablement, and process termination.
  • SOAR integration using Shuffle, n8n, or custom webhooks.
  • Alert correlation and multi-stage attack chaining analysis.
  • Case management workflows and evidence preservation protocols.

Compliance and Reporting

  • Mapping to PCI-DSS, HIPAA, GDPR, and NIST controls.
  • Monitoring policies for password strength, encryption, and patching status.
  • Scheduled report generation and data export functions.
  • Maintaining audit trail integrity and detecting tampering.

Dashboards and Visualization

  • Customizing Wazuh dashboards and creating widgets.
  • Integrating Grafana for advanced visualization needs.
  • Ensuring Kibana compatibility for legacy Elastic environments.
  • Designing views for executive oversight and operational SOC use.

Maintenance and Scaling

  • Managing indexer shards and implementing hot-warm-cold archiving.
  • Establishing log retention policies and legal hold procedures.
  • Disaster recovery planning and cluster rebuild strategies.

Requirements

  • Intermediate proficiency in Linux and Windows system administration.
  • Comprehensive understanding of SIEM concepts, including correlation, alerting, and log aggregation.
  • Practical experience with the Elastic Stack or OpenSearch.

Target Audience

  • Security operations centers seeking to transition from commercial SIEM solutions.
  • Compliance teams requiring on-premise log retention capabilities.
  • Government agencies requiring sovereign threat detection and monitoring infrastructure.
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories