Leveraging the Wazuh Ingestion Ecosystem for Advanced Threat Hunting
This post demonstrates an approach to advanced threat hunting using Wazuh telemetry. It shows how analysts can begin with detections in wazuh-alerts-*, investigate additional telemetry in wazuh-archives-*, and correlate Windows process information to reconstruct suspicious activity. The post demonstrates this approach using PowerShell execution, post-exploitation reconnaissance, named-pipe activity, and ClickFix-related clipboard activity.