Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 
 
 

Repository files navigation

🔐 Wazuh SIEM Deployment & Endpoint Monitoring

📖 Overview

This repository contains my hands-on implementation of a Wazuh SIEM Deployment project completed during my Blue Team learning journey.

The project demonstrates how to deploy a centralized Security Information and Event Management (SIEM) solution using Wazuh, connect Windows and Linux endpoints, configure File Integrity Monitoring (FIM), and investigate generated security alerts.


🎯 Project Objectives

  • Deploy the Wazuh Virtual Appliance
  • Configure the Wazuh Manager
  • Install Wazuh Agent on Windows
  • Install Wazuh Agent on Linux (Parrot Security OS)
  • Configure File Integrity Monitoring (FIM)
  • Generate security events
  • Verify alerts using the Wazuh Dashboard

🖥️ Lab Environment

Component Details
SIEM Wazuh
Hypervisor Oracle VirtualBox
Server Wazuh Virtual Appliance
Windows Endpoint Windows 11
Linux Endpoint Parrot Security OS 6.4
Network Bridged Adapter

📌 Skills Demonstrated

  • SIEM Deployment
  • Blue Team Operations
  • Threat Hunting
  • File Integrity Monitoring (FIM)
  • Endpoint Security
  • Windows Administration
  • Linux Administration
  • Log Analysis

📄 Project Report

The complete implementation report is available in the report folder.


👨‍💻 Author

Huzaifa Saeed

Cybersecurity Student | SOC Analyst Aspirant

About

Hands-on Wazuh SIEM deployment with Windows and Linux endpoints, File Integrity Monitoring (FIM), and Threat Hunting.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors