Wazuh v2.0 released!

Hi everyone,
we are happy to announce that Wazuh v2.0 has just been released!
As many of you already know, it includes the integration of our forked version of OSSEC with OpenSCAP and Elastic Stack 5. In addition, we improved some core capabilities for infrastructure security monitoring and developed a new WUI in the form of a Kibana app.
Here are the highlights of the new release of Wazuh v2.0:
We realized that OSSEC’s ability to monitor system configurations is limited. This is why we decided to incorporate OpenSCAP as an agent component. It allows users to check that the systems are configured according to the company policy or well known standards like CIS (Center of Internet Security) hardening guides.
This means that, via OpenSCAP, we now support OVAL (Open Vulnerability Assessment Language) checks. We have put together default templates for well-known platforms (RedHat, Fedora, CentOS, Ubuntu, and Debian) using OVAL checks provided by CIS repository.
Now the agent is able to run checks periodically and report back to the manager, where alerts are generated, using new decoders and rules (developed using the new dynamic fields feature). Alerts include a description, a check rationale, references, and CCE or CVE identifiers.
We natively support PCI DSS by mapping alerts with compliance controls. This includes not only the alerts triggered by the log analysis engine but also the ones that come from OpenSCAP scans (OVAL checks). We also provide compliance dashboards in the web user interface.
We support integration with Elastic 5, and have built a WUI in the form of a Kibana APP for configuration and status monitoring.
We would also like to thank our developers, contributors, and users. We are looking forward to your feedback, so please don’t hesitate to post on our mailing list if you have any questions about Wazuh v2.0. You can also join our #community Slack channel.