Cybersecurity Homelab – Deploying Wazuh Agents on macOS, Linux & Windows
Let's deploy Wazuh agents on all the endpoints in my house!
Let's deploy Wazuh agents on all the endpoints in my house!
Autonomous Detection, Response & Recovery on AWS using Wazuh and a SOAR Orchestrator
Full technical report attached and GitHub repository
This is an experiment in giving Wazuh alerts an AI-driven triage and response layer.
Establishing dynamic generation of agent.groups.
In this part, we’ll fix exactly that and make sure Keycloak users get full administrator access inside Wazuh.
Automating URL reputation lookups and turning urlscan.io verdicts into severity-based Wazuh alerts.
The article explains that Wazuh flags CVEs for old, unused kernel packages left installed on RHEL-family systems (like Rocky Linux) due to the installonly_limit setting, and shows how to safely identify and remove those outdated kernels with dnf repoquery/dnf remove (verified with –assumeno first) so the Vulnerability-Detection inventory resolves the stale findings.