Section 1: The SOC and the Role of the Blue Team
What a SOC is and the roles of Tier 1 to Tier 3 analysts
The SOC workflow from detection and triage to analysis and response
Metrics used to measure SOC work, such as MTTD and MTTR
Alert fatigue and ways to reduce false positives
An overview of threats commonly seen by Thai organisations and what a SOC needs to see
Section 2: SIEM, XDR and the Wazuh Architecture
How SIEM, EDR and XDR differ and how they work together
Wazuh components: indexer, server, dashboard and agents
How data travels from an agent through decoders and rules to become an alert
All-in-one, distributed and Docker deployment options
Sizing the servers and planning data retention
Section 3: Lab: Installing Wazuh with Docker
Prepare the host and the system settings the Wazuh indexer needs
Install a single-node Wazuh deployment with Docker Compose
Generate certificates and change the default passwords securely
Explore the Wazuh dashboard: overview, endpoints and modules
Lab: check service status and fix common installation problems
Section 4: Lab: Deploying Agents on Linux and Windows
Agent enrolment and how agents communicate with the server
Install agents on Linux and Windows with the commands the dashboard generates
Group agents and use centralised configuration through agent.conf
Check agent status and troubleshoot agents that do not connect
Lab: bring Linux and Windows machines into the system and view the first events
Section 5: Lab: Collecting Syslog, Windows Events and Sysmon Logs
Collect log files on Linux and receive syslog from network devices
Choose the Windows event channels that matter for security
Install Sysmon with a sensible configuration and forward its events to Wazuh
Search and filter events in the dashboard with queries and filters
Lab: track processes and network connections on Windows through Sysmon