deepfence / deepfence/ThreatMapper

Threatmapper and Wazuh SIEM integration

Open
#2,041 1 comment 1 reaction 1 assignee Claimed by @ibreakthecloud View on GitHub
enhancement needs-triage
Dominant language
TypeScript
Stars
5.3k
Forks
631
PR merge metrics
No merged PRs in 30d

Description

Problem:
Existing Wazuh SIEM users lack seamless integration with Threatmapper, hindering efficient correlation and analysis of vulnerability data.

Solution:
Implement native integration between Threatmapper and Wazuh SIEM, allowing automatic ingestion of vulnerability information into Wazuh's indexing platform (e.g., OpenSearch).

Components/Services:

API/Backend

Deployment/YAMLs

Proposed Workflow:

Threatmapper identifies vulnerabilities across assets (Hosts, Docker images and containers).
Vulnerability data is formatted and ingested into Wazuh SIEM Indexer (Opensearch).
Wazuh indexes and correlates this data with existing security event data.
Security analysts leverage Wazuh's dashboard and querying capabilities for comprehensive threat analysis and response.

Additional Context:
This integration streamlines vulnerability management, enhancing security posture by providing centralized visibility and facilitating prioritized remediation efforts.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.