Building a Telegram-Based AI Troubleshooter for Wazuh SIEM

Building a Telegram-Based AI Troubleshooter for Wazuh SIEM

March 25th 2026 / Ambassadors
By Joel Yang / Medium

How I combined LangGraph, Ollama, and a locally hosted LLM to create an on-call diagnostic assistant that SSHes into my Wazuh fleet and answers questions in plain English — from my phone.

Read more
Blocking Brute-Force Attack

Blocking Brute-Force Attack

March 24th 2026 / Ambassadors
By Hafiz Javid / LinkedIn

Blocking the attacker’s IP is good. Locking the targeted account at the same time is better because IPs can change, accounts can’t escape a lock.
This tutorial shows how to configure two Wazuh active responses that fire simultaneously on a single brute-force detection: firewall-drop + disable-account.

Read more
Automating Threat Intelligence Alerts in Wazuh: A Practical Homelab Pipeline

Automating Threat Intelligence Alerts in Wazuh: A Practical Homelab Pipeline

March 23rd 2026 / Ambassadors
By Federico Fantini / Federico Fantini's Blog

A complete, reproducible Wazuh homelab setup that automates TI feed ingestion, normalizes & deduplicates indicators, updates Wazuh CDB lists, correlates with Sysmon/Suricata telemetry, and sends alerts to Discord.

Read more
Wazuh Indexer and needrestart on Ubuntu 24.04 Server: Understanding and Fixing the Java False Positive

Wazuh Indexer and needrestart on Ubuntu 24.04 Server: Understanding and Fixing the Java False Positive

March 21st 2026 / Ambassadors
By Stephan Wenderlich / Gray-Hat Security Consulting Blog

German – If you run the Wazuh Indexer on a hardened Ubuntu 24.04 server, you encounter an apparent issue after every apt upgrade: needrestart reports that the Wazuh Indexer needs to be restarted, even though the service is running stably and the installed updates have nothing to do with the indexer.

Read more
Wazuh + AWS Bedrock: AI Security in Docker (Part 1)

Wazuh + AWS Bedrock: AI Security in Docker (Part 1)

March 16th 2026 / Ambassadors
By Yuriy Medvedev / Blog Pytoshka

In this series we take a parallel path: using AWS Bedrock – specifically Claude Sonnet 4.5 – as the inference backend, while all security data stays strictly within the local Docker network.

Read more