How Wazuh Detects Advanced DLL/Remote Thread Injection Attacks (MITRE T1055)

How Wazuh Detects Advanced DLL/Remote Thread Injection Attacks (MITRE T1055)

>
September 29th 2025 / Ambassadors
By Ludovic Gildas Doamba / Medium

In this guide, we will: Create a custom DLL and a C++ injector, Inject this DLL into Paint using its PID, Use Visual Studio to compile and run the code and Understand how Wazuh can detect this type of advanced injection

September 29th 2025 / Ambassadors

How Wazuh Detects Advanced DLL/Remote Thread Injection Attacks (MITRE T1055)

By Ludovic Gildas Doamba / Medium

In this guide, we will: Create a custom DLL and a C++ injector, Inject this DLL into Paint using its PID, Use Visual Studio to compile and run the code and Understand how Wazuh can detect this type of advanced injection

Read more

>
Mastering Wazuh Cluster Diagnostics: Tackling “Cluster is Not Running” and Beyond.

Mastering Wazuh Cluster Diagnostics: Tackling “Cluster is Not Running” and Beyond.

>
September 28th 2025 / Ambassadors
By Wilklins Nyatteng / Medium

This guide bypasses the generic advice and dives into the methodical, technical steps required to diagnose, fix, and stabilize your Wazuh cluster.

September 28th 2025 / Ambassadors

Mastering Wazuh Cluster Diagnostics: Tackling “Cluster is Not Running” and Beyond.

By Wilklins Nyatteng / Medium

This guide bypasses the generic advice and dives into the methodical, technical steps required to diagnose, fix, and stabilize your Wazuh cluster.

Read more

>
Wazuhevtx

Wazuhevtx

>
September 27th 2025 / Ambassadors
By Zafer Balkan / GitHub

A Python tool and library that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.

September 27th 2025 / Ambassadors

Wazuhevtx

By Zafer Balkan / GitHub

A Python tool and library that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.

Read more

>
High Level Integration — Wazuh & HPE Aruba Networking

High Level Integration — Wazuh & HPE Aruba Networking

>
September 25th 2025 / Ambassadors
By Vigan Bytyqi / Medium

The article describes how to integrate Wazuh with HPE Aruba ClearPass by forwarding ClearPass logs via syslog to Wazuh for centralized monitoring and analysis.

September 25th 2025 / Ambassadors

High Level Integration — Wazuh & HPE Aruba Networking

By Vigan Bytyqi / Medium

The article describes how to integrate Wazuh with HPE Aruba ClearPass by forwarding ClearPass logs via syslog to Wazuh for centralized monitoring and analysis.

Read more

>
Setting UP Wazuh — Server Side Configurations

Setting UP Wazuh — Server Side Configurations

>
September 23rd 2025 / Ambassadors
By Dzidula Gati / Medium

The article outlines key server‑side configurations for Wazuh, including installing on Ubuntu (recommended: 22.04, minimum 8 GB RAM, 4 vCPUs, 50 GB storage).
It covers setting up log retention policies, installing additional decoders/rules (e.g. from SOC Fortress), and securing the server via firewall rules and system hardening (e.g. using Lynis).
Finally, it cautions about upgrade risks, advising disabling the Wazuh repository before doing a general apt upgrade to avoid breaking Wazuh itself.

September 23rd 2025 / Ambassadors

Setting UP Wazuh — Server Side Configurations

By Dzidula Gati / Medium

The article outlines key server‑side configurations for Wazuh, including installing on Ubuntu (recommended: 22.04, minimum 8 GB RAM, 4 vCPUs, 50 GB storage).
It covers setting up log retention policies, installing additional decoders/rules (e.g. from SOC Fortress), and securing the server via firewall rules and system hardening (e.g. using Lynis).
Finally, it cautions about upgrade risks, advising disabling the Wazuh repository before doing a general apt upgrade to avoid breaking Wazuh itself.

Read more

>
Securing Wazuh- A Guide to Keycloak OAuth2 & MFA Integration

Securing Wazuh- A Guide to Keycloak OAuth2 & MFA Integration

>
September 22nd 2025 / Ambassadors
By Mattias Hemmingsson / Life and Shell

It’s time to connect Wazuh to a modern authentication provider. This guide will walk you through integrating Wazuh with Keycloak, a powerful open-source Identity and Access Management (IAM) solution.

September 22nd 2025 / Ambassadors

Securing Wazuh- A Guide to Keycloak OAuth2 & MFA Integration

By Mattias Hemmingsson / Life and Shell

It’s time to connect Wazuh to a modern authentication provider. This guide will walk you through integrating Wazuh with Keycloak, a powerful open-source Identity and Access Management (IAM) solution.

Read more

>
Automating Wazuh Deployments with Docker and Terraform: From Lab to Real-World Environments

Automating Wazuh Deployments with Docker and Terraform: From Lab to Real-World Environments

>
September 22nd 2025 / Ambassadors
By Ismael Barrantes / Medium

The article argues that combining Docker and Terraform enables smooth, repeatable deployment of Wazuh—from quick lab setups to full-scale production environments.
Docker provides portability and ease for bundle-based deployments, while Terraform codifies and automates the underlying infrastructure.
Together, they allow security teams to deploy, scale, tear down, and reproduce Wazuh environments reliably and consistently.

September 22nd 2025 / Ambassadors

Automating Wazuh Deployments with Docker and Terraform: From Lab to Real-World Environments

By Ismael Barrantes / Medium

The article argues that combining Docker and Terraform enables smooth, repeatable deployment of Wazuh—from quick lab setups to full-scale production environments.
Docker provides portability and ease for bundle-based deployments, while Terraform codifies and automates the underlying infrastructure.
Together, they allow security teams to deploy, scale, tear down, and reproduce Wazuh environments reliably and consistently.

Read more

>
CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews

CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews

>
September 20th 2025 / Ambassadors
By Taylor Walton / YouTube

We’ve added two new overview dashboards to CoPilot, powered by Wazuh: the SCA Overview and the Vulnerability Overview. These give you a big-picture view across all your clients, with filters that make it easy to spot your most insecure endpoints in seconds.

September 20th 2025 / Ambassadors

CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews

By Taylor Walton / YouTube

We’ve added two new overview dashboards to CoPilot, powered by Wazuh: the SCA Overview and the Vulnerability Overview. These give you a big-picture view across all your clients, with filters that make it easy to spot your most insecure endpoints in seconds.

Read more

>
Installing Velociraptor using Wazuh Active Response on Windows endpoints

Installing Velociraptor using Wazuh Active Response on Windows endpoints

>
September 19th 2025 / Ambassadors
By Dominik Sigl / iSecNG

The post explains how to integrate Velociraptor as an active response tool with Wazuh on Windows endpoints to enhance incident response capabilities.

September 19th 2025 / Ambassadors

Installing Velociraptor using Wazuh Active Response on Windows endpoints

By Dominik Sigl / iSecNG

The post explains how to integrate Velociraptor as an active response tool with Wazuh on Windows endpoints to enhance incident response capabilities.

Read more

>