
Explore XDR, extended detection and response, and how it unifies data across endpoints, networks, cloud workloads, identities, and applications for proactive threat detection and faster incident response.
Explore the differences between CM, EDR, XDR, and MDR, and learn how each technology or service tracks, analyzes, and responds to security threats across endpoints, networks, and clouds.
Explore the OASU components—manager, agent, indexer, and dashboard—and see how they enable threat detection, visibility, and compliance across endpoints, servers, cloud workloads, and containers.
Explore all-in-one, single-node, and multinode deployment models for Wazuh XDR. Discover how high availability, fault tolerance, and capacity planning shape performance and security.
Install Ubuntu Linux on a virtual machine using Oracle VirtualBox, configure memory and disk, choose language and network, complete interactive installation, then install guest additions for better display.
Install Wazo on Ubuntu Linux using an all-in-one setup, update packages, install curl, run the installer, reboot to verify proxies, then access the Wazo dashboard with the admin credentials.
Download Windows Server 2019 from the Microsoft Evaluation Center, install it in a VirtualBox, configure the VM, set the administrator password, and install the Guest Additions.
Configure Active Directory and DNS on Windows Server by installing roles, promoting a domain controller for a new forest named test.com, and setting DNS forwarders to 8.8.8.8 and 1.1.1.1.
Install the wazuh agent on Windows using CMD or PowerShell with admin rights, or deploy from the wazuh dashboard, start the agent, and review vulnerabilities, alerts, and MITRE ATT&CK data.
Create a host-only internal network for wazuh and Windows servers, set manual IP addresses (10.0.0.2 and 10.0.0.1 as gateway), and verify connectivity with a ping.
Configure windows logs via group policy and advanced audit policies, add app, sysmon, defender, and powershell modules to wazuh agent, forward to wazuh server, then restart.
Discover Sysmon, a Windows system service that logs rich telemetry for deep visibility and incident response, enabling threat hunting and integration with SIEM and XDR.
Install Sysmon on Windows server by downloading the Sysmon zip and a GitHub configuration file, extracting them, and running the installer in PowerShell. Verify it starts automatically by inspecting services.
Configure VirusTotal integration with the Wazoo server to automatically scan suspicious downloads using Yara and delete files via an automation rule, and monitor results in the Wazoo dashboard.
Wasu decoders parse logs from endpoints and devices, extracting fields such as source and destination, usernames, event IDs, and actions, while decoder hierarchy refines parsing via parent and child decoders.
Create your first decoder in Wazoo using decoder syntax and regex, define pre-match and field orders, test with sample logs, and explore hierarchical decoding for dynamic logs.
Create and test your custom rule in Wazoo by organizing local rules, decoders, and groups. Configure rule ID, level, status, and description, then verify with a rule set test.
Set up the Wazo MCP server as a bridge between the Wazo scene and the Cloud AI agent, verify services, install Rust, configure API access, and test agents and alerts.
Analyze Windows alerts with the Wazuh MCP by running port tests, inspecting suspicious file activity, reviewing VirusTotal detections, and applying active response containment within cloud-connected threat intelligence and threat hunting.
Celebrate your progress in Wazuh XDR from beginner to expert and reflect on cybersecurity learning. Invite feedback, ask questions, and stay connected to advance your knowledge and career.
In this course, you will explore Extended Detection and Response (XDR) using Wazuh, a powerful open-source security platform. You will learn how to deploy and configure Wazuh, collect and analyze logs, detect security threats, and respond to incidents across endpoints, servers, and cloud environments.
Also, you'll learn how to integrate it with many different platforms and AI agents.
At first glance, Wazuh XDR may seem complex, but this course is designed to show you how practical and approachable it can be when explained step by step.
This training is ideal for both beginners and experienced cybersecurity professionals. You will be guided through real-world use cases, from building a security monitoring environment to detecting attacks and performing incident response like a SOC analyst. The course focuses on hands-on learning and real scenarios, going beyond theory.
All tools used throughout the course are free and open-source, making this training accessible to anyone who wants to develop practical XDR and SOC skills. The content is structured to be easy to follow while still delivering value to more advanced learners.
I am committed to keeping this course up to date by adding new lessons, labs, and improvements as Wazuh evolves.
If you have any questions, suggestions, or feedback, feel free to reach out. I’m always open to connecting and helping you get the most out of this course.