Wazuh.
Open-source security monitoring platform we deploy for detection, log analysis and host telemetry.
01 What it is
Wazuh combines host-based intrusion detection, log analysis and security monitoring in an open-source platform, deployable as agents plus a central manager.
02 Where it fits
Endpoint telemetry and detection, log correlation, and file integrity monitoring, particularly where an open-source, self-hosted platform fits the organisation's data residency or budget requirements better than a commercial SIEM.
03 Architecture
Agents on monitored hosts report to a central manager and indexer; detection rules are tuned against your actual environment rather than left at defaults that generate excessive noise.
04 XOOPIE expertise
Wazuh is a platform we genuinely deploy and tune as part of our monitoring and cybersecurity services — this is real, hands-on operational experience, not a name on a slide.
05 Integration
Integrates with Elastic/OpenSearch for storage and search, and correlates with firewall and network logs for a fuller picture than host telemetry alone.
06 Deployment considerations
Detection rules are tuned incrementally after deployment, since default rulesets are rarely well matched to a specific environment's normal behaviour.
07 Monitoring & security
Central to our monitoring service — file integrity, log analysis and detection alerts all flow through here into the coverage reporting we provide monthly.
08 Limitations
Open-source and self-hosted means the operational burden of tuning and maintaining it sits with whoever runs it — which is part of what this service provides.
09 Alternatives we also work with
- SentinelOne and CrowdStrike Falcon (commercial EDR, where that fits better)
- Microsoft Defender for Endpoint (in Microsoft-centric estates)