
1.1 - Introduction to the Course
1.2 - Wazuh-Single vs. Wazuh-Multi Architect Difference
2.1 - Download and Installation of VirtualBox
2.2 - Download and Installation of Ubuntu (Wazuh-Server)
2.3 - Change the Language and Keyboard Layout of Ubuntu
2.4 - Download and Installation of Windows 10 (Wazuh-Agent)
3.1 - Update of the Ubuntu Server + Necessary Configurations
3.2 - Installation of Docker + Docker-Compose
3.3 - Creation of Our SOC Directory
4.1 - Installation of Portainer in Docker Mode
4.2 - Main Commands Used in Docker
4.3 - Introduction to Portainer
5.1 - Download of Wazuh in Docker Mode
5.2 - Difference in File Structure Between Wazuh-Single and Wazuh-Multi
5.3 - Changing Admin, Wazuh-wui, and Kibana Passwords
5.4 - Error with Special Character
5.5 - Overview of wazuh_manager.conf
5.6 - Creating the Wazuh Stack in Portainer
5.7 - Mapping and Creation of Variables
5.8 - Overview of Wazuh Directories Inside Portainer
5.9 - Container Management Portainer vs Docker
6.1 - Creating Groups for Agents in Wazuh
6.2 - Configure Static IP on Ubuntu (Important)
6.3 - Installation of Firewall and Open Ports on Ubuntu (Important)
6.4 - Password Authentication for Agents
6.5 - Managing Agents in Wazuh
6.6 - Wazuh Update
6.7 - Agent Update
6.8 - Enabling SCA and Vulnerabilities Modules
6.9 - Enabling the File Integrity Monitor (FMI) Module
7.1 - Introduction to Endpoint Security
7.2 - Introduction to Threat Intelligence
7.3 - Introduction to Security Operation
8.1 - What is Sysmon
8.2 - Integration of Sysmon in Wazuh
8.3 - Installation of Sysmon on Windows
8.4 - What is YARA
8.5 - YARA Installation for Linux
8.6 - YARA Community Rules
8.7 - YARA - Agent Configuration
8.8 - YARA Configuration in Wazuh
8.9 - Integrating VirusTotal into Wazuh
8.10 - What is AuditD
8.11 - Installation of AuditD on Linux
8.12 - Integration of AuditD in Wazuh Using CDB-LIST
9.1 - Why Use Grafana
9.2 - Installation of Grafana
9.3 - Grafana Connection to Wazuh
10.1 - Installation of AtomicRed-Team
10.2 - T1053.005 - Create Rule and Execute Simulated Attack
10.3 - T1053.005 - Log Analysis in Wazuh
10.4 - T1053.005 - Threat Hunting and Dashboard Creation
10.5 - T1218.010 - Create Rule and Execute Simulated Attack
10.6 - T1218.010 - Log Analysis in Wazuh
10.7 - T1218.010 - Threat Hunting and Dashboard Creation
10.8 - T1518.001 - Create Rule and Execute Simulated Attack
10.9 - T1518.001 - Log Analysis in Wazuh
10.10 - T1518.001 - Threat Hunting and Dashboard Creation
Descrição do Curso:
Este curso foi desenvolvido para mostrar, de forma prática, como construir um ambiente de SOC funcional utilizando o Wazuh. A proposta é sair da teoria e trabalhar com cenários reais, entendendo como um SIEM funciona no dia a dia e como ele pode ser utilizado para monitoramento e resposta a incidentes.
Você não vai apenas instalar a ferramenta. O foco está em entender o comportamento dos logs, organizar a coleta de eventos e transformar dados em algo útil para análise de segurança. Ao longo do curso, você irá montar um ambiente completo e validar, na prática, como ataques acontecem e como podem ser identificados.
Durante o curso, você irá aprender:
Como fazer o deploy do Wazuh em Docker utilizando Portainer
Como integrar fontes de log relevantes em ambientes Windows e Linux
Como utilizar Sysmon e Auditd para melhorar a visibilidade do ambiente
Como criar dashboards no Grafana para análise de eventos
Como utilizar YARA e VirusTotal para identificação de ameaças
Como simular ataques reais com Atomic Red Team
Como analisar eventos e iniciar um processo de investigação
Como estruturar um ambiente voltado para operações de SOC
O curso também aborda conceitos importantes como redução de ruído, organização de logs e análise prática de eventos. A ideia é criar uma base sólida para quem deseja evoluir em SOC, Threat Hunting e Engenharia de Detecção.
Se você quer entender como um ambiente de segurança realmente funciona na prática, este curso é o ponto de partida.