Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Wazuh XDR from Beginner to Expert
Rating: 5.0 out of 5(3 ratings)
27 students

Wazuh XDR from Beginner to Expert

Hands-On Threat Detection and Response with Wazuh XDR
Last updated 5/2026
English
English [Auto],

What you'll learn

  • Students will learn how to deploy, configure, and operate Wazuh as an XDR platform to detect, investigate, and respond to security threats
  • Understand XDR concepts and gain hands-on skills to monitor endpoints, analyze logs, and automate incident response with Wazuh
  • How to use Wazuh XDR for threat detection, SOC operations, MITRE ATT&CK mapping, and real-world incident response
  • Building a SOC with Wazuh XDR, including log analysis, threat hunting, and automated security responses.

Course content

6 sections23 lectures4h 32m total length
  • What is XDR6:09

    Explore XDR, extended detection and response, and how it unifies data across endpoints, networks, cloud workloads, identities, and applications for proactive threat detection and faster incident response.

  • The difference between Siem, EDR, XDR, and MDR.5:39

    Explore the differences between CM, EDR, XDR, and MDR, and learn how each technology or service tracks, analyzes, and responds to security threats across endpoints, networks, and clouds.

  • Wazuh Components9:48

    Explore the OASU components—manager, agent, indexer, and dashboard—and see how they enable threat detection, visibility, and compliance across endpoints, servers, cloud workloads, and containers.

  • Deployment models in Wazuh.6:09

Requirements

  • Basic knowledge of Linux and networking
  • Basic fundamental cybersecurity concepts
  • Basic command-line skills and networking fundamentals.

Description

In this course, you will explore Extended Detection and Response (XDR) using Wazuh, a powerful open-source security platform. You will learn how to deploy and configure Wazuh, collect and analyze logs, detect security threats, and respond to incidents across endpoints, servers, and cloud environments.

Also, you'll learn how to integrate it with many different platforms and AI agents.

At first glance, Wazuh XDR may seem complex, but this course is designed to show you how practical and approachable it can be when explained step by step.

This training is ideal for both beginners and experienced cybersecurity professionals. You will be guided through real-world use cases, from building a security monitoring environment to detecting attacks and performing incident response like a SOC analyst. The course focuses on hands-on learning and real scenarios, going beyond theory.

All tools used throughout the course are free and open-source, making this training accessible to anyone who wants to develop practical XDR and SOC skills. The content is structured to be easy to follow while still delivering value to more advanced learners.

I am committed to keeping this course up to date by adding new lessons, labs, and improvements as Wazuh evolves.

If you have any questions, suggestions, or feedback, feel free to reach out. I’m always open to connecting and helping you get the most out of this course.

Who this course is for:

  • Designed for security professionals, blue team members, and anyone looking to learn XDR using an open-source platform.
  • Ideal for beginners and professionals who want to build, operate, or improve a SOC using Wazuh XDR.