Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding the compliance and cost risks associated with cloud-based SIEMs for log retention.
- Overview of Wazuh architecture: server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Implementing single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests for setup.
- Determining hardware sizing (CPU, RAM, disk IOPS) for optimal log ingestion.
- Configuring certificates and TLS for secure component communication.
Agent Management
- Deploying agents via packages, Ansible playbooks, or Group Policy Objects (GPO).
- Managing agent enrollment, key exchange, and group assignments.
- Setting up agentless monitoring through syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large fleets.
Detection Engineering
- Creating decoders and rules for log parsing and event extraction.
- Mapping rule categories to the MITRE ATT&CK framework.
- Implementing file integrity monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence from sources such as MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Executing active response actions like firewall blocking, account disabling, and process termination.
- Integrating with SOAR platforms such as Shuffle, n8n, or custom webhooks.
- Correlating alerts to identify multi-stage attack chains.
- Managing cases and preserving digital evidence.
Compliance and Reporting
- Mapping controls to PCI-DSS, HIPAA, GDPR, and NIST standards.
- Monitoring policies for password strength, encryption standards, and patching status.
- Scheduling report generation and exporting data.
- Ensuring audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating widgets.
- Integrating with Grafana for advanced visualizations.
- Utilizing Kibana compatibility for legacy Elastic deployments.
- Designing executive and operational SOC views.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold archiving strategies.
- Defining log retention policies and legal hold procedures.
- Executing disaster recovery plans and cluster rebuilds.
Requirements
- Intermediate-level proficiency in Linux and Windows system administration.
- Familiarity with SIEM concepts, including log aggregation, correlation, and alerting mechanisms.
- Previous experience working with the Elastic Stack or OpenSearch.
Audience
- SOC teams planning to replace commercial SIEM solutions.
- Compliance departments requiring on-premise log retention capabilities.
- Government agencies that need sovereign threat detection infrastructure.
21 Hours
Testimonials (1)
The trainer was helpful..