Wazuh Community Rulesets

Wazuh Community Rulesets

October 1st 2026 / Ambassadors
By Marco Teixeira / LinkedIn

All Wazuh rules and decoders brought together in one place. Over 110 community sources plus the Wazuh blog: 16,500+ rules, 5,300+ decoders and 479 packs, each file unchanged and credited to its original author.

Read more
Detect a Quartet of Linux Local Root Vulnerabilities with Wazuh 4.14.8

Detect a Quartet of Linux Local Root Vulnerabilities with Wazuh 4.14.8

September 30th 2026 / Ambassadors
By Kislley Rodrigues / GitHub

Detection has to be behavioral, at the syscall level. This repository provides auditd sensor rules and Wazuh detection rules built on four axes, plus an SCA policy that checks the sensor and the exploit prerequisites on each endpoint:

Read more
Inventory: Computer Park Management with Wazuh

Inventory: Computer Park Management with Wazuh

September 29th 2026 / Ambassadors
By Marcus de Almeida / LinkedIn

Wazuh’s open and extensible architecture makes it a foundation the community can build on. Wazuh Ambassador Marcus de Almeida did exactly that with INVENTORY, an open-source asset management layer powered by the data Wazuh already collects through SysCollector.

Read more
Building Wazuh-AFD (Anti-Forensics Detection & Automated Active Response Framework)

Building Wazuh-AFD (Anti-Forensics Detection & Automated Active Response Framework)

September 26th 2026 / Ambassadors
By Muhammad Usman / Medium

This engineering manual provides a comprehensive, step-by-step blueprint for building Wazuh-AFD (Anti-Forensics Detection): an enterprise-grade detection and automated active response framework. Designed for cybersecurity students, junior analysts, and security engineers

Read more
Understanding Wazuh Rules, part II – Metadata and Conditions

Understanding Wazuh Rules, part II – Metadata and Conditions

September 26th 2026 / Ambassadors
By Zafer Balkan / Blog

Instead of asking where a rule sits in the ruleset, I want to ask what a single rule contains once you open it, and how the same structure tells you what to write when the rule does not exist yet. I want to open up one of those nodes now, to see what a rule contains and how that structure helps when you need to write a rule that does not exist yet.

Read more
Validating Windows Security Controls with Wazuh: From Configuration to Detection

Validating Windows Security Controls with Wazuh: From Configuration to Detection

September 24th 2026 / Ambassadors
By Vladislav Kharlamov / LinkedIn

What happens when a hardened Windows environment actually changes? This contribution picks up where Group Policy, Defender, and access restrictions leave off, tracing evidence end-to-end. From Windows event generation through Sysmon and audit policy, into Wazuh collection, custom detection rules, and the analyst who reviews the alert. Working through hands-on exercises like encoded PowerShell, privileged group changes, scheduled tasks, and registry persistence, the author separates what a test actually proves: collection, detection, response, or prevention, from what it doesn’t, and shows how to build detections whose coverage, limitations, and validation method are fully documented rather than assumed.

Read more
Integrating Wazuh and SSDeep Fuzzy Hashing for malware detection

Integrating Wazuh and SSDeep Fuzzy Hashing for malware detection

September 24th 2026 / Ambassadors
By Muhammad Ali / Medium

What Happens When Your Threat Intel Doesn’t Recognize Malware With a Slightly Changed Hash? A story about a question every SOC eventually runs into — and the fuzzy-hashing detection pipeline I built in Wazuh to answer it.

Read more