Decoder Studio
Build Wazuh decoders that actually work, from a handful of sample logs.
Build Wazuh decoders that actually work, from a handful of sample logs.
Running Microsoft Defender XDR alongside Wazuh? Learn how to unify incidents, alerts, and Defender for Cloud events in a single Wazuh dashboard using custom rules, with no more switching between consoles.
All Wazuh rules and decoders brought together in one place. Over 110 community sources plus the Wazuh blog: 16,500+ rules, 5,300+ decoders and 479 packs, each file unchanged and credited to its original author.
Wazuh meets NCA ECC: a community pack maps Saudi Essential Cybersecurity Controls (ECC-2:2024) to native Wazuh capabilities, with no extra agents and no built-in rules modified.
Detection has to be behavioral, at the syscall level. This repository provides auditd sensor rules and Wazuh detection rules built on four axes, plus an SCA policy that checks the sensor and the exploit prerequisites on each endpoint:
Wazuh’s open and extensible architecture makes it a foundation the community can build on. Wazuh Ambassador Marcus de Almeida did exactly that with INVENTORY, an open-source asset management layer powered by the data Wazuh already collects through SysCollector.
How technique mapping works in Wazuh 4.x today, and how it changes in the 5.0 beta
This engineering manual provides a comprehensive, step-by-step blueprint for building Wazuh-AFD (Anti-Forensics Detection): an enterprise-grade detection and automated active response framework. Designed for cybersecurity students, junior analysts, and security engineers