Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source SIEM Sovereignty
- Understanding the compliance and cost risks associated with cloud-based SIEMs for log retention.
- Overview of Wazuh architecture: server, indexer, dashboard, and agents.
- Comparative analysis with Splunk, Sentinel, Elastic Security, and QRadar.
Deployment and Architecture
- Implementing single-node and distributed deployment patterns.
- Utilizing Docker Compose and Kubernetes manifests for deployment.
- Hardware sizing considerations: CPU, RAM, and disk IOPS for log ingestion.
- Configuring certificates and TLS for secure component communication.
Agent Management
- Installing agents via packages, Ansible playbooks, or Group Policy Objects (GPO).
- Managing agent enrollment, key exchange, and group assignment.
- Implementing agentless monitoring through syslog, AWS S3, or API polling.
- Strategies for upgrading agents across large-scale fleets.
Detection Engineering
- Creating decoders and rules for log parsing and event extraction.
- Mapping rules to MITRE ATT&CK framework categories.
- Implementing file integrity monitoring (FIM) and rootkit detection.
- Writing custom rules using XML and YAML syntax.
- Integrating threat intelligence from MISP, VirusTotal, and AlienVault.
Incident Response and Automation
- Executing active responses such as firewall blocking, account disabling, and process termination.
- Integrating with SOAR platforms like Shuffle, n8n, or custom webhooks.
- Correlating alerts to identify multi-stage attack chains.
- Managing cases and preserving forensic evidence.
Compliance and Reporting
- Mapping controls for PCI-DSS, HIPAA, GDPR, and NIST frameworks.
- Monitoring policies regarding password strength, encryption standards, and patching levels.
- Scheduling report generation and exporting data.
- Ensuring audit trail integrity and detecting tampering.
Dashboards and Visualization
- Customizing Wazuh dashboards and creating custom widgets.
- Integrating with Grafana for advanced visualization needs.
- Leveraging Kibana compatibility for legacy Elastic deployments.
- Designing views tailored for executive and operational SOC teams.
Maintenance and Scaling
- Managing indexer shards and implementing hot-warm-cold data archiving.
- Defining log retention policies and handling legal holds.
- Executing disaster recovery procedures and cluster rebuilding.
Requirements
- Intermediate proficiency in Linux and Windows system administration.
- Fundamental understanding of SIEM concepts, including correlation, alerting, and log aggregation.
- Practical experience with the Elastic Stack or OpenSearch.
Audience
- SOC teams aiming to replace commercial SIEM solutions.
- Compliance departments requiring on-premise log retention capabilities.
- Government agencies needing sovereign threat detection infrastructure.
21 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication