This repository contains my hands-on implementation of a Wazuh SIEM Deployment project completed during my Blue Team learning journey.
The project demonstrates how to deploy a centralized Security Information and Event Management (SIEM) solution using Wazuh, connect Windows and Linux endpoints, configure File Integrity Monitoring (FIM), and investigate generated security alerts.
- Deploy the Wazuh Virtual Appliance
- Configure the Wazuh Manager
- Install Wazuh Agent on Windows
- Install Wazuh Agent on Linux (Parrot Security OS)
- Configure File Integrity Monitoring (FIM)
- Generate security events
- Verify alerts using the Wazuh Dashboard
| Component | Details |
|---|---|
| SIEM | Wazuh |
| Hypervisor | Oracle VirtualBox |
| Server | Wazuh Virtual Appliance |
| Windows Endpoint | Windows 11 |
| Linux Endpoint | Parrot Security OS 6.4 |
| Network | Bridged Adapter |
- SIEM Deployment
- Blue Team Operations
- Threat Hunting
- File Integrity Monitoring (FIM)
- Endpoint Security
- Windows Administration
- Linux Administration
- Log Analysis
The complete implementation report is available in the report folder.
Huzaifa Saeed
Cybersecurity Student | SOC Analyst Aspirant