Become an ambassador

"What I love about Wazuh is that it treats security as a community problem, not a vendor product. The ruleset is open, the architecture is transparent, and when something's missing you can just build it. That philosophy is rare in security tooling. What pulled me deeper was realising how much of the real-world attack surface isn't covered yet. Caddy is one of the fastest-growing web servers right now and had zero detection coverage in Wazuh. That's not a niche gap. And the fact that I could sit down, write a decoder and 29 MITRE ATT&CK-mapped rules, validate them end-to-end in Docker, and ship a PR in a week is a direct result of how well-designed the Wazuh architecture is. Beyond detection engineering, I find the XDR angle genuinely interesting. Wazuh correlating endpoint telemetry, cloud logs, and network events into one place without a licensing wall is something even paid platforms struggle to do cleanly. I want to understand every layer of that stack, contribute to it, and eventually work on it full time."