Validating Windows Security Controls with Wazuh: From Configuration to Detection

Validating Windows Security Controls with Wazuh: From Configuration to Detection

September 24th 2026 / Ambassadors
By Vladislav Kharlamov / LinkedIn

What happens when a hardened Windows environment actually changes? This contribution picks up where Group Policy, Defender, and access restrictions leave off, tracing evidence end-to-end. From Windows event generation through Sysmon and audit policy, into Wazuh collection, custom detection rules, and the analyst who reviews the alert. Working through hands-on exercises like encoded PowerShell, privileged group changes, scheduled tasks, and registry persistence, the author separates what a test actually proves: collection, detection, response, or prevention, from what it doesn’t, and shows how to build detections whose coverage, limitations, and validation method are fully documented rather than assumed.

Read more
Integrating Wazuh and SSDeep Fuzzy Hashing for malware detection

Integrating Wazuh and SSDeep Fuzzy Hashing for malware detection

September 24th 2026 / Ambassadors
By Muhammad Ali / Medium

What Happens When Your Threat Intel Doesn’t Recognize Malware With a Slightly Changed Hash? A story about a question every SOC eventually runs into — and the fuzzy-hashing detection pipeline I built in Wazuh to answer it.

Read more
SOP: Wazuh Configuration File (ossec.conf)

SOP: Wazuh Configuration File (ossec.conf)

September 22nd 2026 / Ambassadors
By Mirza Muhammad Ahmed / LinkedIn

A practical SOP covering one of Wazuh’s most central files: ossec.conf. The guide breaks down the configuration file’s key sections — from global settings and remote connections to active response and email alerts — and walks through common operational tasks step by step, including whitelisting IPs, forwarding alerts to external syslog servers, configuring email notifications, ingesting network device logs, and monitoring new log files.

Read more
Wazuh SIEM Ransomware Protection

Wazuh SIEM Ransomware Protection

September 21st 2026 / Ambassadors
By Maryam Liaqat / Medium

This lab demonstrates how Wazuh SIEM detects and responds to real ransomware activity on a Windows endpoint. The lab follows the official Wazuh blog methodology and covers: Pre-Execution detection, Active Response, Sysmon Monitoring, FIM Monitoring.

Read more
BrandSentinel: Building an Automated Brand Impersonation and Typosquatting Detection Integration for Wazuh

BrandSentinel: Building an Automated Brand Impersonation and Typosquatting Detection Integration for Wazuh

September 18th 2026 / Ambassadors
By Muhammad Moiz Uddin Rafay / Medium

Explore a custom integration that extends Wazuh’s visibility beyond internal infrastructure to catch phishing and brand impersonation before they reach users. The tool automatically generates look-alike domain variations, enriches them with RDAP, DNS, TLS, and hosting intelligence, applies a risk-scoring engine, and forwards suspicious findings straight into Wazuh — turning external domain monitoring into another correlated data source inside the SOC.

Read more