AgentSecOps / AgentSecOps/SecOpsAgentKit

skill request: Wazuh XDR for unified EDR, SIEM, and compliance monitoring

Đang mở
#20 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
detection enhancement incident-response new-skill
Ngôn ngữ chính
Python
Star
209
Fork
39
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

## Summary

The `incident-response` category has strong forensics coverage (osquery, Velociraptor, Sigma) but no unified EDR/SIEM skill. Wazuh is the leading open-source XDR/SIEM platform combining endpoint detection, log analysis, file integrity monitoring, and compliance dashboards in a single agent+manager architecture. It fills a critical gap between post-incident forensics and real-time detection.

## Requested Skill: `incident-response/detection-wazuh`

### What to Cover

**Core workflows**:

1. **Agent deployment and enrollment**
```bash
# Install agent and register to manager
WAZUH_MANAGER='10.0.0.2' WAZUH_AGENT_NAME='web-prod-01' \
apt install wazuh-agent && systemctl start wazuh-agent
```

2. **Custom detection rules** — write rules that trigger on specific log patterns
```xml

5402
COMMAND=/bin/bash
Sudo to bash shell detected - possible privilege escalation
T1548.003

```

3. **File Integrity Monitoring** — detect unauthorized changes to critical files
```xml


/etc,/usr/bin,/usr/sbin

```

4. **Active response** — auto-block IPs triggering brute-force rules
```xml

firewall-drop
local
5763
600

```

5. **Compliance dashboards** — query PCI-DSS, HIPAA, GDPR compliance status via API

### Integration with Existing Skills

- **Sigma rules** (`detection-sigma`) can be converted to Wazuh XML rules using `sigma convert -t wazuh`
- **osquery** results can be forwarded to Wazuh as custom log sources
- Wazuh alerts can trigger Velociraptor hunts for deep forensic collection

### Frameworks

- MITRE ATT&CK (native integration in Wazuh dashboard)
- PCI-DSS Req 10 (logging), Req 11.4 (IDS/IPS)
- HIPAA § 164.312(b) (Audit Controls)
- GDPR Article 32 (security of processing)
- NIST CSF DE.CM (Continuous Monitoring)
- CIS Controls v8 — Control 8 (Audit Log Management), Control 13 (Network Monitoring)

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.