Security Monitoring with Wazuh & Suricata Without Agents on Production Servers

Security Monitoring with Wazuh & Suricata Without Agents on Production Servers

April 13th 2026 / Ambassadors
By Ludovic Gildas Doamba / Medium

This lab demonstrates an alternative approach: deploying a dedicated probe server in promiscuous mode, equipped with Suricata and a Wazuh agent, in order to detect multiple categories of web attacks without installing any agent on the target application server.

Read more
Automated DoS Mitigation

Automated DoS Mitigation

April 9th 2026 / Ambassadors
By Hafiz Javid / LinkedIn

This time I configured Wazuh to detect a SYN flood attack using a custom rule and a custom decoder that extracts the attacker’s IP from iptables kernel logs.

Read more
SOC Detection Egineering Lab

SOC Detection Egineering Lab

April 9th 2026 / Ambassadors
By Tareif Suliman / LinkedIn

SOC lab to simulate a realistic phishing based attack chain and explore how Security Operations Center teams can detect malicious activity using endpoint telemetry and SIEM correlation with Wazuh.

Read more
Why Your SOC Needs better Thinking

Why Your SOC Needs better Thinking

April 2nd 2026 / Ambassadors
By Hazem Mohammed / LinkedIn

The article explains how to reduce alert noise with Wazuh, proactively detect threats, and reinvest savings into team training.

Read more
Sophos Firewall Integration with Wazuh SIEM

Sophos Firewall Integration with Wazuh SIEM

April 2nd 2026 / Ambassadors
By Muhammad Moiz Uddin Rafay / Medium

This guide outlines the complete process of integrating a Sophos XG/XGS Firewall with the Wazuh SIEM platform.

Read more
Wazuh, Zeek and Pi-hole DNS Sinkhole on Repurposed Hardware (TV Box)

Wazuh, Zeek and Pi-hole DNS Sinkhole on Repurposed Hardware (TV Box)

April 1st 2026 / Ambassadors
By Kislley Rodrigues / Medium

This project transforms a decommissioned low-cost TV Box into an operational network security node, combining DNS-level threat blocking with deep packet inspection, centralized log aggregation, and external threat intelligence enrichment.

Read more
Wazuh Stormshield Custom Rule+Decoder

Wazuh Stormshield Custom Rule+Decoder

April 1st 2026 / Ambassadors
By Raphael Tchonkoteu / Medium

The article explains how to integrate Stormshield firewall logs into Wazuh by creating custom decoders and rules to properly parse data, enable accurate alerting, and improve detection and response capabilities.

Read more