Detecting Windows attacks with Microsoft Defender ASR and Wazuh 

Detecting Windows attacks with Microsoft Defender ASR and Wazuh 

Post icon
/ Engineering
By

Attackers often abuse legitimate Windows features and applications to execute malicious code, steal credentials, establish persistence, and evade security controls. Detecting these behaviors early helps security teams identify suspicious activity before it leads to further compromise. Microsoft Defender Attack Surface Reduction (ASR) rules help protect Windows endpoints by restricting behaviors commonly abused by malware and […]

Read more
Detecting AWS access key compromise with Wazuh

Detecting AWS access key compromise with Wazuh

Post icon
/ Engineering
By

AWS access keys are credentials that applications, users, and automation tools use to authenticate to AWS services through APIs. Each key consists of an access key ID and a secret access key. The associated IAM identity determines which AWS resources and operations the credentials can access. When access keys are exposed through public repositories, build […]

Read more
Detecting Langflow CVE-2026-33017 exploitation with Wazuh

Detecting Langflow CVE-2026-33017 exploitation with Wazuh

Post icon
/ Engineering
By

Langflow is an open source, low-code platform for building and deploying AI-powered agents and workflows. These workflows, called flows, define how AI models, prompts, and other components interact to process a request. Organizations can publish flows as HTTP endpoints, allowing applications and users to interact with them remotely. Exposing these endpoints to the internet increases […]

Read more
Detecting unauthorized SUID and SGID binaries with Wazuh

Detecting unauthorized SUID and SGID binaries with Wazuh

Post icon
/ Engineering
By

SUID (Set User ID) and SGID (Set Group ID) are special Linux file permission bits. They allow a program to run with the privileges of the file owner or group rather than the user who launches it. Legitimate binaries such as passwd, sudo, and chage rely on these bits to perform privileged operations safely. Attackers […]

Read more
Scanning Kubernetes infrastructure against CIS Benchmark with Wazuh

Scanning Kubernetes infrastructure against CIS Benchmark with Wazuh

Post icon
/ Engineering
By

Kubernetes is widely used for orchestrating containerized workloads. Securing a Kubernetes cluster requires configuring control-plane components, worker nodes, and workloads according to security best practices. As Kubernetes clusters evolve through upgrades and operational changes, maintaining secure configurations becomes increasingly challenging. The CIS Kubernetes Benchmark provides security recommendations for hardening Kubernetes clusters, including control-plane components, worker […]

Read more
Automating security reporting and response with Wazuh and Shuffle

Automating security reporting and response with Wazuh and Shuffle

Post icon
/ Engineering
By

Security teams process large volumes of alerts each day, which makes it difficult to identify recurring threats, prioritize incidents, and respond consistently. While continuous monitoring is essential, organizations can also benefit from scheduled summaries that consolidate alert activity over a defined period. These reports help analysts recognize patterns, surface recurring issues, and track risk trends […]

Read more
Monitoring end-of-life software with Wazuh

Monitoring end-of-life software with Wazuh

Post icon
/ Engineering
By

Software reaches end-of-life (EOL) when vendors end standard support for a product or version, including regular security updates. Organizations that continue using EOL software face increased security risks because newly discovered vulnerabilities may no longer receive security patches from the vendor, leaving systems exposed to known and potentially exploitable vulnerabilities. Despite the security risks, EOL […]

Read more
Detecting common Linux privilege escalation techniques with Wazuh

Detecting common Linux privilege escalation techniques with Wazuh

Post icon
/ Engineering
By

Privilege escalation is the process by which an attacker gains permissions beyond those assigned to their current account. On Linux systems, threat actors who gain initial access as a low-privileged user often exploit misconfigurations or weak security controls to obtain root or other privileged access. With elevated privileges, they can disable security controls, modify system […]

Read more
Real-time threat correlation with Wazuh and OpenCTI

Real-time threat correlation with Wazuh and OpenCTI

Post icon
/ Engineering
By

Modern security operations need deep visibility into endpoints, networks, and cloud workloads, combined with actionable, real‑time intelligence about active threats and adversaries. Without this context, security teams struggle to distinguish high‑priority threats from benign events and low‑value alerts, slowing down investigations and increasing attacker dwell time. Wazuh provides unified visibility and threat detection across your […]

Read more
Defending against the RoguePlanet vulnerability with Wazuh

Defending against the RoguePlanet vulnerability with Wazuh

Post icon
/ Engineering
By

Microsoft Defender is one of the most widely deployed security solutions, shipping out of the box with Windows 10, Windows 11, and Windows Server releases. A newly disclosed zero-day vulnerability, known as RoguePlanet (tracked as CVE-2026-50656), affects how Microsoft Defender handles specific file operations during malware remediation. Successful exploitation can allow an attacker with access […]

Read more
Detecting Stratus Red Team adversary emulation on Microsoft Azure with Wazuh

Detecting Stratus Red Team adversary emulation on Microsoft Azure with Wazuh

Post icon
/ Engineering
By

Microsoft Azure is a cloud computing platform that provides scalable infrastructure, storage, networking, identity management, and security services. Organizations use Azure to host critical workloads, manage enterprise applications, and support hybrid and cloud-native environments. At the core of Microsoft Azure identity infrastructure is Microsoft Entra ID, which manages identities, authentication, and access to cloud resources. […]

Read more
Managing shadow IT with Wazuh

Managing shadow IT with Wazuh

Post icon
/ Engineering
By

Shadow IT refers to technology resources, including hardware, software, services, and user accounts, used without the approval or oversight of IT and security teams. This can include remote access tools, cloud storage applications, AI tools, peer-to-peer clients, cryptocurrency miners, unsanctioned SaaS services, cracked software, and other unauthorized technologies. These unauthorized resources create visibility gaps because […]

Read more
Keep up to date
with our digest of articles