OpenCTI integration

OpenCTI integration

May 20th 2026 / Ambassadors
By Federico Fantini / GitHub

OpenCTI can expose shared data through different native feeds, including Live streams, TAXII collections, and CSV feeds. For this integration, I chose a TAXII collection because it exposes STIX 2.1 bundles through a standard API and provides a pagination model that is straightforward to automate.

Read more
How to Turn Wazuh Into an AI-Powered Security Assistant Using Claude

How to Turn Wazuh Into an AI-Powered Security Assistant Using Claude

May 20th 2026 / Ambassadors
By Ahmed Abdelrazek / Medium

By connecting Wazuh to Claude Desktop using MCP (Model Context Protocol), you can talk to your SIEM like you’d talk to a colleague. No complex queries. No dashboard hopping. Just ask, and get answers.

Read more
Building an Enhanced Windows Endpoint Monitoring Lab with Wazuh + Sysmon on AWS

Building an Enhanced Windows Endpoint Monitoring Lab with Wazuh + Sysmon on AWS

May 19th 2026 / Ambassadors
By Maryam Liaqat / Medium

By the end of this walkthrough, you will learn how to deploy Sysmon using an industry-standard configuration, forward Sysmon telemetry into Wazuh, create custom detection rules for persistence and process injection, and validate detections using simulated attack activity.

Read more
Designing Effective Monitoring with Wazuh

Designing Effective Monitoring with Wazuh

May 19th 2026 / Ambassadors
By Michael Theumert / GitHub

A common mistake in monitoring design is collecting too many metrics without understanding their purpose. More data does not mean better monitoring. It often means more noise. Effective monitoring focuses on a small number of high-value signals that clearly indicate when something is wrong.

Read more
Detecting Dirty Frag (CVE-2026-43284 and CVE-2026-43500) with Wazuh 4.14.4One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

Detecting Dirty Frag (CVE-2026-43284 and CVE-2026-43500) with Wazuh 4.14.4One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

May 19th 2026 / Ambassadors
By Kislley Rodrigues / LinkedIn

One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

Read more