Introduction To Wazuh SIEM

Поділитися
Вставка
  • Опубліковано 27 гру 2024

КОМЕНТАРІ • 55

  • @securehcid5651
    @securehcid5651 2 роки тому +9

    Great evolution. From replacement OSSEC as HIDS to all in one security solution (SIEM+XDR).

  • @DingDingPanic
    @DingDingPanic 2 роки тому +18

    The new version of Wazuh no longer has ELK onboard. It has been replaced with a native search and indexing solution. The gui is now different too. Would like to see this video redone based around the new version.

  • @nullproxyYT
    @nullproxyYT 2 роки тому +50

    For everyone who's reading this, wish you an amazing day! 🔥❤

  • @plushplush7635
    @plushplush7635 2 роки тому +2

    very good topics with snort and wazuh, thanks

  • @primescope6874
    @primescope6874 2 роки тому +3

    Great.. Looking forward to the next one in this series.

  • @durgeshgupta863
    @durgeshgupta863 2 роки тому +2

    need more video related to Wazuh SIEM

  • @VidarPT
    @VidarPT 7 місяців тому

    Does anyone know where I can get access to the rest of the series? There are 3 videos related to WAZUH on this channel, but in the description there's link for a part 2 in all of them. Problem is the link doesn't work and the uploader seems to be gone... Thanks.

  • @QueenShebaCEO
    @QueenShebaCEO Рік тому +1

    Thank you this was a great breakdown of this SIEM

  • @InfinitiCyberSolutions
    @InfinitiCyberSolutions Рік тому

    In preparation for this lab I installed and configured the Security Onion iso. How can I use it with this lab please?

  • @emaneezechiel4164
    @emaneezechiel4164 2 роки тому +1

    Great info, you got a new subscriber

  • @sunmoon2005
    @sunmoon2005 2 роки тому +2

    Thank you so much as you do for teaching us

  • @StevieRayLou
    @StevieRayLou Рік тому

    Can wazuh 4.5.2 be installed on debian12? Can you make a flatpak, please?

  • @logicfirst7959
    @logicfirst7959 2 роки тому +3

    You know in my red team/blue team engagement, the very first thing i did was to disable beat and Splunk UF and blue team was completely blind and oblivious of any attacks.

    • @killacups
      @killacups Рік тому +2

      From a blue team's perspective, disabling of UF/EDR would trigger a detection right away. Or, if logging stops coming in.

    • @logicfirst7959
      @logicfirst7959 Рік тому

      @@killacups there hasn't been a single case in the last 10 years when detection triggered upon killing the UF/Beat process.

    • @killacups
      @killacups Рік тому +1

      Sorry, my answer was a bit more generalized. This completely depends on the environment.

    • @dennisTHEmenac3
      @dennisTHEmenac3 Рік тому

      Once elastic drops their update with their own native agents, wazuh will be useless. I’ve only ever used endgame for host agent (enterprise deployment) and if you’re somehow able to kill the endgame agent, it absolutely triggers an alert. Still can’t believe wazuh or beats doesn’t trigger on disable. That’s a huge open source gap if true

  • @Sodara-168
    @Sodara-168 2 роки тому +1

    Does the Wazuh support with App logs?

  • @PetritK10
    @PetritK10 2 роки тому +2

    Whats difference between Wazuh and Splunk

    • @felixbecker5591
      @felixbecker5591 2 роки тому

      They are different products for logging. If you look into the Pricelists, you will see the difference 😂

    • @Born_rebel1992
      @Born_rebel1992 2 роки тому

      By using wazuh you will reduce logs size which you sending to splunk.you can use wazuh as filter for spending important logs to splunk.

  • @Hacking_vibe
    @Hacking_vibe 2 роки тому +2

    Setup and config video podunga bro

  • @tshakh9345
    @tshakh9345 Рік тому

    Do someone know ho to change ip adress of wazuh after installation?

  • @Almir-Targino
    @Almir-Targino День тому

    Obrigado!! thanks!!

  • @AbdulWahid-ig6ep
    @AbdulWahid-ig6ep 2 роки тому

    No setup video?

  • @bluerewind7044
    @bluerewind7044 2 роки тому +1

    Thanks for the help!

  • @cagoaustine7194
    @cagoaustine7194 Рік тому

    please sir can u make us video on pegasus

  • @georgesherpa
    @georgesherpa 2 роки тому

    isnt wazuh EDR/XDR? is it just a siem?

    • @felixbecker5591
      @felixbecker5591 2 роки тому +1

      It’s EDR/XDR yes. But in combination with ELK it could be used as a SIEM. But I think there are still a lot of missing functionalities

  • @techclubhouse6772
    @techclubhouse6772 2 роки тому +2

    I think am first to watch this

  • @bibeksubedi9245
    @bibeksubedi9245 2 роки тому +1

    Nice, First of all you make Elastic search video. There is lack video becasue you directly jump on wazuh.

  • @johnvardy9559
    @johnvardy9559 9 місяців тому

    Great alexis

  • @goodboy-mn2qp
    @goodboy-mn2qp 7 місяців тому

    great information ❤️❤️🤍

  • @dr.thulaganyorabogadi8596
    @dr.thulaganyorabogadi8596 10 місяців тому

    Monitoring non wazhuh devices

  • @chandraprakashntc
    @chandraprakashntc 2 роки тому +1

    Need hive and s3 bucket integration videos too

    • @Born_rebel1992
      @Born_rebel1992 2 роки тому

      There is video on youtube for s3 bucket integration with wazuh

  • @romeomungiu2932
    @romeomungiu2932 2 роки тому +2

    A lot is still missing, the engine at the base is still ossec with a “signature based type of rules”. Tu much correlation capabilities are missing to call it a siem.
    Of clouds… better then nothing but still, calling it a siem is misleading

    • @javimed9669
      @javimed9669 2 роки тому

      Hi. Wazuh provides threat prevention, detection, and response capabilities and helps with regulatory compliance. It collects logs from disparate sources and analyzes near real time the security events. It also considers historical and contextual data allowing incident management. It has useful dashboards and reporting capabilities. Wazuh is indeed a complete SIEM + XDR platform. Perhaps you would like to discuss particular features you don't find in the product? What are the missing correlation capabilities? Thank you.

  • @imveryhungry112
    @imveryhungry112 11 місяців тому

    I create SIEM put wazu out of business :)

  • @SecurityTalent
    @SecurityTalent 2 роки тому

    Great

  • @ramsaidupati1781
    @ramsaidupati1781 2 роки тому

    👋👍

  • @MontgomeryElsa
    @MontgomeryElsa 3 місяці тому

    9681 Kilback Trail