Become an ambassador

"As a cybersecurity professional and hands-on practitioner, I’ve extensively worked with Wazuh to build a fully functional SIEM and XDR lab environment, integrating logs from Windows, Linux, and firewall agents. I have explored and tested Wazuh’s capabilities in real-time alerting, rule tuning, and threat intelligence correlation. What impressed me most is that while Wazuh’s native features are already comprehensive, its true power is unlocked when combined with custom integrations. I developed custom scripts to enhance Wazuh’s alerting engine. For example, integrating Discord for instant security alerts and combining Wazuh with MISP to flag IOCs and escalate login anomalies. I also configured the platform to raise alerts on multiple failed login attempts from MISP flagged IPs, storing them separately in a custom alert file for refined triage. Wazuh offers the best of both worlds: out-of-the-box enterprise features and the flexibility to adapt to unique use cases. With the ability to write custom rules and integrate external threat feeds, I believe Wazuh is a powerhouse for any organisation serious about open-source security monitoring. I’m excited to contribute to and advocate for the Wazuh community as an Ambassador."