Introduction To Wazuh SIEM

Поделиться
HTML-код
  • Опубликовано: 14 дек 2024

Комментарии • 54

  • @securehcid5651
    @securehcid5651 2 года назад +9

    Great evolution. From replacement OSSEC as HIDS to all in one security solution (SIEM+XDR).

  • @DingDingPanic
    @DingDingPanic 2 года назад +18

    The new version of Wazuh no longer has ELK onboard. It has been replaced with a native search and indexing solution. The gui is now different too. Would like to see this video redone based around the new version.

  • @nullproxyYT
    @nullproxyYT 2 года назад +50

    For everyone who's reading this, wish you an amazing day! 🔥❤

  • @primescope6874
    @primescope6874 2 года назад +3

    Great.. Looking forward to the next one in this series.

  • @plushplush7635
    @plushplush7635 2 года назад +2

    very good topics with snort and wazuh, thanks

  • @VidarPT
    @VidarPT 7 месяцев назад

    Does anyone know where I can get access to the rest of the series? There are 3 videos related to WAZUH on this channel, but in the description there's link for a part 2 in all of them. Problem is the link doesn't work and the uploader seems to be gone... Thanks.

  • @sunmoon2005
    @sunmoon2005 2 года назад +2

    Thank you so much as you do for teaching us

  • @logicfirst7959
    @logicfirst7959 2 года назад +3

    You know in my red team/blue team engagement, the very first thing i did was to disable beat and Splunk UF and blue team was completely blind and oblivious of any attacks.

    • @killacups
      @killacups Год назад +2

      From a blue team's perspective, disabling of UF/EDR would trigger a detection right away. Or, if logging stops coming in.

    • @logicfirst7959
      @logicfirst7959 Год назад

      @@killacups there hasn't been a single case in the last 10 years when detection triggered upon killing the UF/Beat process.

    • @killacups
      @killacups Год назад +1

      Sorry, my answer was a bit more generalized. This completely depends on the environment.

    • @dennisTHEmenac3
      @dennisTHEmenac3 Год назад

      Once elastic drops their update with their own native agents, wazuh will be useless. I’ve only ever used endgame for host agent (enterprise deployment) and if you’re somehow able to kill the endgame agent, it absolutely triggers an alert. Still can’t believe wazuh or beats doesn’t trigger on disable. That’s a huge open source gap if true

  • @QueenShebaCEO
    @QueenShebaCEO Год назад

    Thank you this was a great breakdown of this SIEM

  • @durgeshgupta863
    @durgeshgupta863 2 года назад +1

    need more video related to Wazuh SIEM

  • @emaneezechiel4164
    @emaneezechiel4164 2 года назад +1

    Great info, you got a new subscriber

  • @InfinitiCyberSolutions
    @InfinitiCyberSolutions Год назад

    In preparation for this lab I installed and configured the Security Onion iso. How can I use it with this lab please?

  • @Hacking_vibe
    @Hacking_vibe 2 года назад +2

    Setup and config video podunga bro

  • @StevieRayLou
    @StevieRayLou Год назад

    Can wazuh 4.5.2 be installed on debian12? Can you make a flatpak, please?

  • @PetritK10
    @PetritK10 2 года назад +2

    Whats difference between Wazuh and Splunk

    • @felixbecker5591
      @felixbecker5591 2 года назад

      They are different products for logging. If you look into the Pricelists, you will see the difference 😂

    • @Born_rebel1992
      @Born_rebel1992 2 года назад

      By using wazuh you will reduce logs size which you sending to splunk.you can use wazuh as filter for spending important logs to splunk.

  • @Sodara-168
    @Sodara-168 2 года назад +1

    Does the Wazuh support with App logs?

  • @bluerewind7044
    @bluerewind7044 2 года назад +1

    Thanks for the help!

  • @tshakh9345
    @tshakh9345 Год назад

    Do someone know ho to change ip adress of wazuh after installation?

  • @AbdulWahid-ig6ep
    @AbdulWahid-ig6ep 2 года назад

    No setup video?

  • @cagoaustine7194
    @cagoaustine7194 Год назад

    please sir can u make us video on pegasus

  • @techclubhouse6772
    @techclubhouse6772 2 года назад +2

    I think am first to watch this

  • @johnvardy9559
    @johnvardy9559 8 месяцев назад

    Great alexis

  • @georgesherpa
    @georgesherpa 2 года назад

    isnt wazuh EDR/XDR? is it just a siem?

    • @felixbecker5591
      @felixbecker5591 2 года назад +1

      It’s EDR/XDR yes. But in combination with ELK it could be used as a SIEM. But I think there are still a lot of missing functionalities

  • @bibeksubedi9245
    @bibeksubedi9245 2 года назад +1

    Nice, First of all you make Elastic search video. There is lack video becasue you directly jump on wazuh.

  • @chandraprakashntc
    @chandraprakashntc 2 года назад +1

    Need hive and s3 bucket integration videos too

    • @Born_rebel1992
      @Born_rebel1992 2 года назад

      There is video on youtube for s3 bucket integration with wazuh

  • @dr.thulaganyorabogadi8596
    @dr.thulaganyorabogadi8596 9 месяцев назад

    Monitoring non wazhuh devices

  • @SecurityTalent
    @SecurityTalent 2 года назад

    Great

  • @romeomungiu2932
    @romeomungiu2932 2 года назад +2

    A lot is still missing, the engine at the base is still ossec with a “signature based type of rules”. Tu much correlation capabilities are missing to call it a siem.
    Of clouds… better then nothing but still, calling it a siem is misleading

    • @javimed9669
      @javimed9669 2 года назад

      Hi. Wazuh provides threat prevention, detection, and response capabilities and helps with regulatory compliance. It collects logs from disparate sources and analyzes near real time the security events. It also considers historical and contextual data allowing incident management. It has useful dashboards and reporting capabilities. Wazuh is indeed a complete SIEM + XDR platform. Perhaps you would like to discuss particular features you don't find in the product? What are the missing correlation capabilities? Thank you.

  • @imveryhungry112
    @imveryhungry112 10 месяцев назад

    I create SIEM put wazu out of business :)

  • @ramsaidupati1781
    @ramsaidupati1781 2 года назад

    👋👍

  • @goodboy-mn2qp
    @goodboy-mn2qp 7 месяцев назад

    great information ❤️❤️🤍

  • @MontgomeryElsa
    @MontgomeryElsa 2 месяца назад

    9681 Kilback Trail