Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding why cloud-based SIEMs pose compliance and cost risks for log retention.
- Wazuh architecture: server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Single-node and distributed deployment patterns.
- Docker Compose and Kubernetes manifests.
- Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
- Certificate and TLS configuration for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or Group Policy Objects (GPO).
- Agent enrollment, key exchange, and group assignment processes.
- Agentless monitoring options using syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large fleets.
Detection Engineering
- Using decoders and rules for log parsing and event extraction.
- Mapping rule categories to MITRE ATT&CK techniques.
- File integrity monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence feeds from MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Active response mechanisms: firewall blocking, account disabling, and process termination.
- SOAR integration with Shuffle, n8n, or custom webhooks.
- Alert correlation and analysis of multi-stage attack chains.
- Case management and evidence preservation procedures.
Compliance and Reporting
- Mapping controls from PCI-DSS, HIPAA, GDPR, and NIST frameworks.
- Monitoring policies for password strength, encryption standards, and patching levels.
- Scheduled report generation and export functionality.
- Maintaining audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing the Wazuh dashboard and creating widgets.
- Integrating Grafana for advanced visualizations.
- Kibana compatibility for legacy Elastic deployments.
- Tailored views for executives and operational SOC teams.
Maintenance and Scaling
- Indexer shard management and hot-warm-cold data archiving.
- Implementing log retention policies and legal hold procedures.
- Disaster recovery planning and cluster rebuild processes.
Requirements
- Intermediate knowledge of Linux and Windows system administration.
- Understanding of SIEM concepts, including correlation, alerting, and log aggregation.
- Experience with the Elastic Stack or OpenSearch.
Audience
- Security operations centers seeking to replace commercial SIEM solutions.
- Compliance teams requiring on-premise log retention capabilities.
- Government agencies needing sovereign threat detection mechanisms.
21 Hours
Testimonials (1)
The trainer was helpful..