deepfence / deepfence/ThreatMapper
Threatmapper and Wazuh SIEM integration
- Dominant language
- TypeScript
- Stars
- 5.3k
- Forks
- 631
- PR merge metrics
- No merged PRs in 30d
Description
Problem:
Existing Wazuh SIEM users lack seamless integration with Threatmapper, hindering efficient correlation and analysis of vulnerability data.
Solution:
Implement native integration between Threatmapper and Wazuh SIEM, allowing automatic ingestion of vulnerability information into Wazuh's indexing platform (e.g., OpenSearch).
Components/Services:
API/Backend
Deployment/YAMLs
Proposed Workflow:
Threatmapper identifies vulnerabilities across assets (Hosts, Docker images and containers).
Vulnerability data is formatted and ingested into Wazuh SIEM Indexer (Opensearch).
Wazuh indexes and correlates this data with existing security event data.
Security analysts leverage Wazuh's dashboard and querying capabilities for comprehensive threat analysis and response.
Additional Context:
This integration streamlines vulnerability management, enhancing security posture by providing centralized visibility and facilitating prioritized remediation efforts.
Contributor guide
Assessment
This issue has not been assessed yet.