Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding the compliance and cost risks associated with cloud-based SIEMs for log retention.
- Overview of Wazuh architecture: server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Implementing single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests.
- Determining hardware sizing for CPU, RAM, and disk IOPS based on log ingestion needs.
- Configuring certificates and TLS for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or Group Policy Objects (GPO).
- Managing agent enrollment, key exchange, and group assignment.
- Implementing agentless monitoring through syslog, AWS S3, or API polling.
- Executing agent upgrade strategies across extensive fleets.
Detection Engineering
- Configuring decoders and rules for log parsing and event extraction.
- Mapping rule categories to the MITRE ATT&CK framework.
- Implementing file integrity monitoring (FIM) and rootkit detection.
- Developing custom rules using XML and YAML syntax.
- Integrating threat intelligence feeds from MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Executing active response actions such as firewall blocking, account disabling, and process termination.
- Integrating SOAR platforms like Shuffle, n8n, or custom webhooks.
- Correlating alerts and analyzing multi-stage attack chains.
- Managing cases and preserving forensic evidence.
Compliance and Reporting
- Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST standards.
- Monitoring policies regarding password strength, encryption, and patch management.
- Scheduling report generation and exporting data.
- Ensuring audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating widgets.
- Integrating Grafana for advanced visualizations.
- Leveraging Kibana compatibility for legacy Elastic deployments.
- Designing executive and operational SOC views.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold data archiving.
- Establishing log retention policies and legal hold procedures.
- Executing disaster recovery plans and cluster rebuilds.
Requirements
- Intermediate proficiency in Linux and Windows system administration.
- Understanding of SIEM concepts including correlation, alerting, and log aggregation.
- Experience with the Elastic Stack or OpenSearch.
Audience
- Security operations centers transitioning from commercial SIEMs.
- Compliance teams requiring on-premise log retention capabilities.
- Government agencies needing sovereign threat detection solutions.
21 Hours
Testimonials (1)
The trainer was helpful..