There are 7 repositories under wazuh topic.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Wazuh - Docker containers
Plugins for Wazuh Dashboard
Wazuh - Ruleset
Wazuh - Ansible playbook
Wazuh - Project documentation
SIAC is an enterprise SIEM built on open-source technology.
Wazuh - Tools for packages creation
SOAR Automation with Shuffle, Wazuh & TheHive | This project integrates Shuffle SOAR, Wazuh SIEM, and TheHive to automate security incident response. It enriches alerts using VirusTotal & AbuseIPDB, creates incidents in TheHive, and sends real-time Discord notifications.
A Ruleset to enhance detection capabilities of Ossec using Sysmon
WAZUH - The Open Source Security Platform Installation
Sysmon and wazuh integration with Sigma sysmon rules [updated]
Monitoring a Kubernetes cluster involves deploying and utilizing the Wazuh agent within the Kubernetes environment.
Wazuh - Splunk App
Wazuh - Puppet module
Wazuh - Amazon AWS Cloudformation
CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Decoders and Rules for Fortigate in Wazuh
Wazuh - Wazuh Kubernetes Helm chart. This repo is not maintained by Wazuh team. This is community project.
Wazuh prometheus exporter
Wazuh - Chef cookbooks
A configuration to allow Wazuh to communicate with ChatGPT, based on https://loggar.hashnode.dev/augmenting-wazuh-with-chatgpt-integration
Wazuh extension looking up alert data against indicators in OpenCTI threat intel
OpenCTI–Wazuh connector looking for indicators in Wazuh and creating sightings
(Unofficial) Wazuh integration to send alerts to IRIS.
Open-source powered SIEM, Vulnerability Scanning, Host- & Network-IDS. Built upon Elastic Stack, OpenVAS, Suricata. Wrapped in a Python Flask web app.
Django middleware and signals for handling security events
If you a security engineer or an aspirant Security professional then Setting up a Wazuh home lab environment is an excellent way for SOC (Security Operations Center) analysts to gain hands-on experience in security monitoring, alerting, and response.
Wazuh - Release for Bosh.io
An open-source MCP server for integrating Wazuh security data with LLMs (such as the Claude Desktop App). This service authenticates with the Wazuh RESTful API, retrieves alerts from Elasticsearch indices, transforms events into an MCP-compliant JSON format, and exposes an HTTP endpoint for Claude Desktop to fetch real-time security context.
wazuh-integratord - This version is written in Go. It was created to help to parse alerts log and alerting faster.
Kaspersky Security Center: custom decoders and rules for Wazuh SIEM
This project automates SOC workflows using Wazuh, Shuffle, and TheHive. It involves setting up a Windows 10 client with Sysmon and Ubuntu 22.04 for Wazuh and TheHive, deployed on cloud or VMs. Goals: automate event collection, alerting, and incident response to enhance SOC efficiency.