Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding the compliance and cost risks associated with cloud SIEMs for log retention.
- Wazuh architecture: server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests.
- Hardware sizing guidelines: CPU, RAM, and disk IOPS for log ingestion.
- Certificate and TLS configuration for secure component communication.
Agent Management
- Installing agents via packages, Ansible, or GPO.
- Agent enrollment, key exchange, and group assignment.
- Agentless monitoring through syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large fleets.
Detection Engineering
- Developing decoders and rules for log parsing and event extraction.
- Mapping rules to MITRE ATT&CK categories.
- File integrity monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence from MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Active response actions: firewall blocking, account disabling, and process termination.
- S0AR integration with Shuffle, n8n, or custom webhooks.
- Alert correlation and multi-stage attack chaining analysis.
- Case management and evidence preservation.
Compliance and Reporting
- Mapping controls for PCI-DSS, HIPAA, GDPR, and NIST.
- Policy monitoring for password strength, encryption, and patching status.
- Scheduled report generation and export functionalities.
- Audit trail integrity and tamper detection mechanisms.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating widgets.
- Grafana integration for advanced visualizations.
- Kibana compatibility for legacy Elastic deployments.
- Tailored views for executives and operational SOC teams.
Maintenance and Scaling
- Indexer shard management and hot-warm-cold archiving strategies.
- Log retention policies and legal hold procedures.
- Disaster recovery planning and cluster rebuild processes.
Requirements
- Intermediate knowledge of Linux and Windows system administration.
- Familiarity with SIEM concepts, including correlation, alerting, and log aggregation.
- Experience working with the Elastic Stack or OpenSearch.
Audience
- Security operations centers seeking to replace commercial SIEMs.
- Compliance teams requiring on-premise log retention capabilities.
- Government agencies needing sovereign threat detection solutions.
21 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication