How to Setup Wazuh - The All In One Security Platform / Intrusion Detection System

preview_player
Показать описание
#DigitalAvenue
In this tutorial I’ll going to demonstrate how to setup Wazuh - The free, open source and enterprise-ready security monitoring solution for threat detection, integrity monitoring, incident response and compliance.

WHAT IS WAZUH?
Wazuh is a free, open source and enterprise-ready security detection and monitoring solution.

Wazuh is born as a fork of OSSEC (HIDS) host based intrusion detection system. Later is was integrated with Elastic stack and OpenSCAP.

Which can perform threat detection, integrity monitoring, incident response and compliance.

Wazuh System consist with several components:
OSSEC HIDS - Host Based Intrusion Detection System
OpenSCAP - Open Vulnerability Assessment Language
Elastic Stack - Filebeat, Elasticsearch, Kibana
Wazuh is loaded with number of valued capabilities.

MAIN FEATURES:
1. SECURITY ANALYTICS:
Wazuh is used to collect, aggregate, index and analyze security data which helping to detect intrusions, threats and anomalies.

Endpoint Detection and Response (EDR)

Wazuh Agent actively perform security analysts discover, investigate and perform block a network attack, stop a malicious process or quarantine a malware infected file.

2. INTRUSION DETECTION
Wazuh-Agent scan the monitored system looking for malware, rootkits and suspicious anomalies. Also It can detect hidden files, clocked processes or unregistered network listeners.

3. LOG DATA ANALYSIS
Wazuh-Agent read operating system and application logs, and forward them to a central Wazuh-Manager for rule-based analysis.

Which helps you to aware of application or system errors,miss-configuration, attempted successful malicious activities, policy violations and many more.

4. FILE INTEGRITY MONITORING
Wazuh monitors the file system, identifying changes in content, permissions, ownership and attributes of files that you need to keep an eye on.

Also It can identify users and applications used to create or modify files.

5. VULNERABILITY DETECTION
Wazuh agent pull software inventory data and send them to the Wazuh Manager server. Then, they matches with CVE (Common Vulnerabilities and Exposure) databases, in order to identify well-know vulnerable software.

Automated vulnerability assessment helps you find the weak spots in your critical assets and take corrective action before attackers exploit them to sabotage your business or steal confidential data.

6. CONFIGURATION ASSESSMENT
Wazuh monitors system and application configuration settings to ensure they are compliant with you security policies and standards.

Agent automatically performs periodic scan to detect applications that are know to be vulnerable, unpatched, or insecurely configured.

And also It alerts recommendations for better configuration and security hardening.

7. INCIDENT RESPONSE
Wazuh take action against active threats such as blocking access from the threat source when certain criteria are met.

8. REGULATORY COMPLIANCE
Wazuh provides some of necessary security controls to become complaint with industry standards and regulations.

9. CLOUD SECURITY
Wazuh helps monitoring cloud infrastructure as an API level. It can pull security data from instances on well known cloud providers such as AWS, Azure, Google Cloud Platform.

10. CONTAINERS SECURITY
Wazhuh provides security visibility into your docker hosts and containers.
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
My Website:
On Facebook:
On Linkedin:
On GitHub:
On Twitter:
You can download pfsense here
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
Music: Inspire by Wavecont
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬

If You want to contact the artist:

CorporateMusic #DigitalAvenue
Рекомендации по теме
Комментарии
Автор

tks for this. 1 suggestion: have your voice volume higher than the music volume

johnnyelkid
Автор

Thanks for the tutorial. I will be glad if you make a tutorial for Wazuh 4 version.

ShohratPermanov
Автор

it's an amazing... Actually i am trying ELK stack for my production environment.. Its an good tool..but i am afraid, client side configuration for wazuh agent... because it's installing multiple packages. i thought it will conflict with my production configuration..how do you think ?

vijay.e
Автор

Hi there i have 3 question please 1.is it like pfsense or opensense?? 2.can we install directly on windows without virtual machine?? 3.can we install on standalone computers and use it and antivirus and firewall like kaspersky ??

Martin-otxj
Автор

Will it monitor logs of systems which are outside network

devendrabendre
Автор

that's great help... could you please copy paste all the commands you have used.... i didn't find...

vaibthekool
Автор

Make a video showing the installation of Elasticsearch & Kibana unattended installation in the version 4.1 documentation

marciolima
Автор

does this work even if your logged (just for personal use on desktop.. no server whatsoever).. or if if it is possible. how can we set it up to work like so?

Hester
Автор

Hi Dimuthu, can u advise how to add authentication for accessing kibana and for agent registration pls. Thank you

shafrazmohamed
Автор

It is Single host architecture or Distributed host architecture ?

hacktheworld
Автор

could you please install with logstash?

izzetsilmovik
Автор

Hi am getting below error while installing the kibana plugin, could you please help to resolve?


Found previous install attempt. Deleting...
Plugin installation was unsuccessful due to error "Cannot delete files/directories outside the current working directory. Can be overridden with the `force` option."

my_responsibility
Автор

can Wazuh detect suspicious user activities as well?

saivenkataratnamemmani
Автор

thank you, but please upload without background music. your voice is sometimes lower than this background music

Fun_with_love
Автор

Hello sir. Can u Share a link commands u used?

SuperChelseaSW
Автор

Can you re-upload without the music please ?

NeelNarayan
Автор

Sir, i want to try install wazuh in centos run on virtual box, please module to instalation step 🙏

DianPratama
Автор

Hello people! I followed the steps of the video, I did the same thing, but I didn't do it locally, I disappeared a hundred server on AWS, but as soon as I enter to open the wazuh it returns this error to me ....

Wazuh API seems to be down
1
Check the Wazuh API service status

For Systemd
$ sudo systemctl status wazuh-api
For SysV Init
$ sudo service wazuh-api status
2
Check the configuration

Review the settings in the file.
# Example Wazuh API configuration
hosts:
- production:
port: 55000
user: foo
password: bar
Test the configuration

Check that the Kibana server can reach the configured Wazuh API(s).

Check connection
Already configured Wazuh API(s)
Below is a table of 1 items.
ID
Host
Port
Status
default
55000
Offline


O que poderia ser??? Deste jeito meu Wazuh nao funciona...

wevertonbatista
Автор

How to configure for Windows & Mac?

NeelNarayan
Автор

i have error //// please set up wazuh api credential

mahmudhashim