Detecting Typo-squatting with Have I Been Squatted and Wazuh SIEM
This article walks through the architecture, implementation approach, detection strategy, and lessons learned while building the integration.
This article walks through the architecture, implementation approach, detection strategy, and lessons learned while building the integration.
In this use case, we install Docker Engine on the Ubuntu Server (where the Wazuh agent is already installed), configure the Wazuh agent to monitor Docker events, and verify that the alerts appear correctly on the Wazuh Dashboard.
This article walks through four of those blind spots, the “under the hood” tuning areas that are rarely discussed but make the difference between a Wazuh deployment that keeps up and one that falls behind.
From security detection to IOC enrichment, investigation, and automated notification using an open-source security stack.
In this blog post, we demonstrate how to configure MinIO as a self-hosted S3-compatible snapshot repository for the Wazuh indexer.
In this Live Demo, I’ll show you how to combine Wazuh FIM, YARA, Active Response and an LLM to create an automated malware detection and alert-enrichment workflow.
Wazuh 4.14.7 ships with 14 system changes across cluster, API, FIM, and cloud layers — including two silent eBPF FIM bugs that caused undetected data loss on Amazon Linux, now resolved. The release also hardens cluster sync, restores cross-account AWS SQS ingestion, and fully removes the legacy wazuh-dbd daemon. Upgrade recommended for affected deployments.
Check if Wazuh’s decoders still match current vendor log formats and found eight of nine integrations had a real gap, with SentinelOne the exception. A newer beta release fixed some issues — the decoder catalog grew from ~140 to ~340 entries, with Cisco Meraki and FTD genuinely fixed, but AWS and Azure unchanged. A second batch of ten more vendors found nine still had uncovered changes, with Cortex XDR the worst gap.