Wazuh NCA ECC Compliance Pack
Wazuh meets NCA ECC: a community pack maps Saudi Essential Cybersecurity Controls (ECC-2:2024) to native Wazuh capabilities, with no extra agents and no built-in rules modified.
Wazuh meets NCA ECC: a community pack maps Saudi Essential Cybersecurity Controls (ECC-2:2024) to native Wazuh capabilities, with no extra agents and no built-in rules modified.
All Wazuh rules and decoders brought together in one place. Over 110 community sources plus the Wazuh blog: 16,500+ rules, 5,300+ decoders and 479 packs, each file unchanged and credited to its original author.
Detection has to be behavioral, at the syscall level. This repository provides auditd sensor rules and Wazuh detection rules built on four axes, plus an SCA policy that checks the sensor and the exploit prerequisites on each endpoint:
Wazuh’s open and extensible architecture makes it a foundation the community can build on. Wazuh Ambassador Marcus de Almeida did exactly that with INVENTORY, an open-source asset management layer powered by the data Wazuh already collects through SysCollector.
This engineering manual provides a comprehensive, step-by-step blueprint for building Wazuh-AFD (Anti-Forensics Detection): an enterprise-grade detection and automated active response framework. Designed for cybersecurity students, junior analysts, and security engineers
Instead of asking where a rule sits in the ruleset, I want to ask what a single rule contains once you open it, and how the same structure tells you what to write when the rule does not exist yet. I want to open up one of those nodes now, to see what a rule contains and how that structure helps when you need to write a rule that does not exist yet.
What happens when a hardened Windows environment actually changes? This contribution picks up where Group Policy, Defender, and access restrictions leave off, tracing evidence end-to-end. From Windows event generation through Sysmon and audit policy, into Wazuh collection, custom detection rules, and the analyst who reviews the alert. Working through hands-on exercises like encoded PowerShell, privileged group changes, scheduled tasks, and registry persistence, the author separates what a test actually proves: collection, detection, response, or prevention, from what it doesn’t, and shows how to build detections whose coverage, limitations, and validation method are fully documented rather than assumed.
What Happens When Your Threat Intel Doesn’t Recognize Malware With a Slightly Changed Hash? A story about a question every SOC eventually runs into — and the fuzzy-hashing detection pipeline I built in Wazuh to answer it.