AgentSecOps / AgentSecOps/SecOpsAgentKit
skill request: Wazuh XDR for unified EDR, SIEM, and compliance monitoring
- 主要語言
- Python
- 星號
- 209
- 分支
- 39
- PR 合併指標
- 30 天內沒有已合併 PR
描述
## Summary
The `incident-response` category has strong forensics coverage (osquery, Velociraptor, Sigma) but no unified EDR/SIEM skill. Wazuh is the leading open-source XDR/SIEM platform combining endpoint detection, log analysis, file integrity monitoring, and compliance dashboards in a single agent+manager architecture. It fills a critical gap between post-incident forensics and real-time detection.
## Requested Skill: `incident-response/detection-wazuh`
### What to Cover
**Core workflows**:
1. **Agent deployment and enrollment**
```bash
# Install agent and register to manager
WAZUH_MANAGER='10.0.0.2' WAZUH_AGENT_NAME='web-prod-01' \
apt install wazuh-agent && systemctl start wazuh-agent
```
2. **Custom detection rules** — write rules that trigger on specific log patterns
```xml
5402
COMMAND=/bin/bash
Sudo to bash shell detected - possible privilege escalation
T1548.003
```
3. **File Integrity Monitoring** — detect unauthorized changes to critical files
```xml
/etc,/usr/bin,/usr/sbin
```
4. **Active response** — auto-block IPs triggering brute-force rules
```xml
firewall-drop
local
5763
600
```
5. **Compliance dashboards** — query PCI-DSS, HIPAA, GDPR compliance status via API
### Integration with Existing Skills
- **Sigma rules** (`detection-sigma`) can be converted to Wazuh XML rules using `sigma convert -t wazuh`
- **osquery** results can be forwarded to Wazuh as custom log sources
- Wazuh alerts can trigger Velociraptor hunts for deep forensic collection
### Frameworks
- MITRE ATT&CK (native integration in Wazuh dashboard)
- PCI-DSS Req 10 (logging), Req 11.4 (IDS/IPS)
- HIPAA § 164.312(b) (Audit Controls)
- GDPR Article 32 (security of processing)
- NIST CSF DE.CM (Continuous Monitoring)
- CIS Controls v8 — Control 8 (Audit Log Management), Control 13 (Network Monitoring)
貢獻指南
這個儲存庫沒有索引到貢獻指南
評估
這個 Issue 還沒有評估資料。