Learn Wazuh (open source SIEM & XDR) from the basics to production-grade: prerequisites & environment setup, history & background, core concepts & main architecture, all-in-one quickstart installation, agent deployment & enrollment, log monitoring & analysis, rules & decoders, file integrity monitoring FIM, active response & malware detection, vulnerability detection, security configuration assessment SCA, GDPR NIST HIPAA PCI DSS compliance, AWS Azure GCP cloud security, Docker & Kubernetes integration, distributed cluster & multi-node architecture, API authentication & security best practice, key encryption & secure agent communication, custom rules & advanced detection, external integration TheHive Shuffle SOAR, performance tuning & capacity planning, monitoring Wazuh itself & backup, modern features & roadmap, through alternative ecosystems & final reflection with a total of 23 episodes.
Opening episode of the Learn Wazuh series: the essential skills you must master before touching the world of SIEM and XDR. Complete with a guide to preparing a VM lab for the Wazuh server and target agents, checking RAM and virtualization, and accessing the official Wazuh 4.x package repository.

Tracing Wazuh's journey from OSSEC HIDS in 2004 through Wazuh 5.0, and the reasons organizations need an affordable open source SIEM. Including the problems it solves: endpoint visibility, FIM, vulnerability scanning, and regulatory compliance.

Understanding Wazuh's core concepts: the differences between SIEM, EDR, and XDR, the five main platform components — manager, indexer, dashboard, agent, and RESTful API — plus the data flow from endpoint to dashboard, along with service verification in the lab.

A practical guide to installing single-node Wazuh 4.x with wazuh-install.sh: system preparation, running the installer, verifying the status of the manager, indexer, and dashboard, plus the first login to the dashboard with a self-signed certificate.

Installing the Wazuh Agent on Linux, Windows, and macOS, enrolling it to the manager, configuring ossec.conf, taking advantage of centralized agent.conf management, and verifying the active agent status from the dashboard and command line.

Exploring how Wazuh reads and analyzes logs: logcollector for local logs and remote syslog, localfile configuration in ossec.conf, the decoder-to-rules-to-alert flow, and viewing events and queries in the Wazuh dashboard.

Getting to know Wazuh decoders and rules: the structure of local_decoder and local_rules, syslog and JSON log formats, how to create custom decoders and custom rules, the match, filter, syscheck, vulnerability, and scan rule types, plus the level scale from 0 to 15 for prioritizing alerts.

Diving into Wazuh's File Integrity Monitoring: the syscheck module for watching important files, comparing realtime and scheduled monitoring, whitelisting directories and Windows registry, plus configuring intervals, checksums, and added, modified, and deleted file change reports.

Bringing automation to life in Wazuh: active response to block IPs, kill processes, and quarantine files via agent commands, complete with timeout and frequency, plus malware detection through rootcheck, YARA integration, and the newest agent malware scan module in Wazuh 4.10.

Exploring Wazuh's Vulnerability Detection module: the vulnerability inventory on agents, CVE feeds from NVD and OSV based on CPE, comparing installed packages against the CVE database, vulnerability detector configuration, scan schedules, the Vulnerabilities dashboard, and Windows patch management.
