Building a Wazuh + Pulsedive Integration From Scratch: Threat Relationship Enrichment for SOC Analysts

Building a Wazuh + Pulsedive Integration From Scratch: Threat Relationship Enrichment for SOC Analysts

September 3rd 2026 / Ambassadors
By Muhammad Ali / Medium

Learn how to build a Wazuh and Pulsedive integration from scratch to enrich security alerts with actionable threat intelligence. This integration helps SOC analysts automate threat enrichment, add context to indicators, and accelerate security investigations.

Read more
Wazuh para ISO/IEC 27001:2022 – Part 1 of 6

Wazuh para ISO/IEC 27001:2022 – Part 1 of 6

September 1st 2026 / Ambassadors
By Fellipe Morgado / Medium

This is the first in a series of six practical technical guides created to demonstrate how Wazuh can automate the collection of evidence for the controls of Annex A of ISO/IEC 27001:2022. Each section will cover specific controls with real-world production codes, decoders, and rules, available in our complementary GitHub repository. This guide serves as the conceptual and technical foundation needed for any professional, even beginners, to start using Wazuh as a compliance audit engine.

Read more
Why You Must Build a Threat Model Before Deploying Wazuh

Why You Must Build a Threat Model Before Deploying Wazuh

September 1st 2026 / Ambassadors
By Syed Jawad / Medium

Installing Wazuh is easy. Running it reliably in production for months or years is not. Most teams install Wazuh, see the green dashboard, and assume everything is fine. A few weeks or months later, they start facing serious problems:
The manager crashes and the entire SOC loses visibility
The dashboard suddenly shows “No results match your search”
Disk fills up and the indexer goes into read-only mode
Adding more agents makes the system slower instead of better
After a reboot, services fail to start properly
These are not random bugs. They are the predictable result of missing threat modeling at deployment time.

In this deep-dive, we’ll build a practical Scalability + Availability Threat Model for Wazuh — complete with real failure stories, architecture progression, sizing guidelines, monitoring metrics, recovery steps, and a production readiness checklist.

Read more
Detecting Shadow AI: Building an Open-Source Framework for Wazuh

Detecting Shadow AI: Building an Open-Source Framework for Wazuh

September 1st 2026 / Ambassadors
By Hamza Jameel / Medium

An open-source Wazuh SIEM framework (custom rules, decoders, wodles, SCA checks, and dashboards) for detecting unauthorized “Shadow AI” tool usage—like local LLMs, AI API calls, and exposed API keys—across an organization’s endpoints.

Read more
Your SIEM Sees Everything. Does It Understand Any of It?

Your SIEM Sees Everything. Does It Understand Any of It?

August 31st 2026 / Ambassadors
By Ryad Serkouh / Medium

Discover how Wazuh integrates MITRE ATT&CK into the security detection workflow, providing analysts with greater context around alerts and attacker techniques. Learn how to use ATT&CK views, extend detection coverage with custom Wazuh rules, and improve threat investigation and prioritization.

Read more
Docker Monitoring with Wazuh

Docker Monitoring with Wazuh

August 27th 2026 / Ambassadors
By Saif Ullah / Medium

In this use case, we install Docker Engine on the Ubuntu Server (where the Wazuh agent is already installed), configure the Wazuh agent to monitor Docker events, and verify that the alerts appear correctly on the Wazuh Dashboard.

Read more