Cybersecurity · CYC-04

SOC and SIEM with Wazuh

SOC and SIEM with Wazuh is a hands-on Blue Team course in building security monitoring with Wazuh, from a Docker install and log collection on Linux, Windows and Sysmon to custom detection rules, FIM, MITRE ATT&CK mapping, active response and threat hunting. It suits system administrators, IT security teams and junior SOC analysts, and you leave with an incident response playbook for your organisation.

Updated
From 8,910 THB / person 9,900 −10% excl. VAT 7% · group rates available
PDFDownload the course outline
  • Duration18 hours · 3 days
  • FormatOnsite / live online
  • Next roundOn request
  • LevelIntermediate

Course overview

Many organisations already have firewalls and antivirus, yet they still cannot see what is happening on their own machines and servers from day to day. Logs are scattered in many places and nobody looks at them until something breaks, so when a real incident happens nobody knows how the attacker got in or what they have already done. The job of a Blue Team and a SOC is to make these events visible early and respond before the damage spreads.

This course has learners build their own security monitoring system with Wazuh, an open source SIEM and XDR platform. It starts with the roles and workflow of a SOC, then installs the Wazuh indexer, server and dashboard with Docker, deploys agents on Linux and Windows and collects logs from syslog, Windows events and Sysmon. Learners then write their own decoders and rules and work with File Integrity Monitoring, vulnerability detection, Security Configuration Assessment and MITRE ATT&CK mapping, before moving on to active response, alerting, threat hunting and attack simulations that are handled with an incident response playbook. It closes with a capstone in which learners act as the SOC team through a full incident. (3 days, 6 hours per day, 18 hours in total, Intermediate level.)

What you’ll gain

  • Understand SOC roles, workflow and metrics, and the ideas behind SIEM and XDR
  • Install Wazuh with Docker and deploy agents on Linux and Windows
  • Collect logs from syslog, Windows events and Sysmon into Wazuh completely
  • Read existing decoders and rules and write custom rules that fit the organisation's systems
  • Use FIM, vulnerability detection and SCA to find weak points on the organisation's machines
  • Map alerts to MITRE ATT&CK and carry out threat hunting on Wazuh data
  • Set up active response and send alerts to email, Slack or webhooks
  • Respond to incidents by following an incident response playbook you have written yourself

Who this course is for

  • System and network administrators who are responsible for their organisation's security
  • Junior SOC analysts and anyone who wants to move into Blue Team work
  • IT security teams looking for an open source SIEM for their organisation
  • DevOps and cloud engineers who need to monitor servers and containers
  • People who have studied ethical hacking and want to understand the defence and detection side

Prerequisites

  • Administrator-level basics on the Linux command line and on Windows
  • Networking fundamentals such as IP addresses, ports, protocols and DNS
  • Basic security knowledge such as malware, brute force attacks and firewalls
  • A laptop with at least 16 GB of RAM that can run Docker Desktop or VirtualBox, with admin rights

Curriculum

Course Details

This is a Blue Team security course focused on monitoring, detecting and responding to threats with Wazuh. It runs for 3 days, 6 hours per day (18 hours in total, 09:00-16:00), as lectures with labs on a SOC lab that learners build themselves on their own machines with Docker. Intermediate level. All tools are open source or free to use, and attack simulations are run only against authorised lab machines. The course complements ethical hacking courses that focus on the attacking side, and it does not cover large clustered Wazuh deployments for production. Learners take home a lab guide, docker-compose files, a set of sample rules and decoders, and an incident response playbook template.

Day 1 SOC Fundamentals and Installing Wazuh

Section 1: The SOC and the Role of the Blue Team

  • What a SOC is and the roles of Tier 1 to Tier 3 analysts

  • The SOC workflow from detection and triage to analysis and response

  • Metrics used to measure SOC work, such as MTTD and MTTR

  • Alert fatigue and ways to reduce false positives

  • An overview of threats commonly seen by Thai organisations and what a SOC needs to see

Section 2: SIEM, XDR and the Wazuh Architecture

  • How SIEM, EDR and XDR differ and how they work together

  • Wazuh components: indexer, server, dashboard and agents

  • How data travels from an agent through decoders and rules to become an alert

  • All-in-one, distributed and Docker deployment options

  • Sizing the servers and planning data retention

Section 3: Lab: Installing Wazuh with Docker

  • Prepare the host and the system settings the Wazuh indexer needs

  • Install a single-node Wazuh deployment with Docker Compose

  • Generate certificates and change the default passwords securely

  • Explore the Wazuh dashboard: overview, endpoints and modules

  • Lab: check service status and fix common installation problems

Section 4: Lab: Deploying Agents on Linux and Windows

  • Agent enrolment and how agents communicate with the server

  • Install agents on Linux and Windows with the commands the dashboard generates

  • Group agents and use centralised configuration through agent.conf

  • Check agent status and troubleshoot agents that do not connect

  • Lab: bring Linux and Windows machines into the system and view the first events

Section 5: Lab: Collecting Syslog, Windows Events and Sysmon Logs

  • Collect log files on Linux and receive syslog from network devices

  • Choose the Windows event channels that matter for security

  • Install Sysmon with a sensible configuration and forward its events to Wazuh

  • Search and filter events in the dashboard with queries and filters

  • Lab: track processes and network connections on Windows through Sysmon

Day 2 Detecting Threats and Assessing Risk

Section 6: Wazuh Decoders and Rules

  • How decoders are structured and how they extract fields from logs

  • How rules are structured: level, group, if_sid and frequency

  • Test logs against decoders and rules with wazuh-logtest

  • Rule evaluation order and tuning levels to suit the organisation

  • Lab: walk through the rules behind a failed SSH login step by step

Section 7: Lab: Writing Custom Decoders and Rules

  • Write a decoder for logs from an in-house application

  • Write rules that build on existing ones to detect unusual behaviour

  • Frequency-based rules for events that repeat within a time window

  • Reduce false positives with exceptions and tighter rule conditions

  • Lab: detect suspicious logins from the logs of a sample web application

Section 8: Lab: File Integrity Monitoring

  • How FIM works and which files and folders are worth watching

  • Configure syscheck for scheduled and real-time monitoring

  • Find out who changed a file with who-data mode on Linux and Windows

  • Monitor the Windows registry keys that attackers use for persistence

  • Lab: catch changes to web files and critical configuration files

Section 9: Lab: Vulnerability Detection and SCA

  • How vulnerability detection finds CVEs from the software inventory on each machine

  • Read vulnerability reports, prioritise by severity and plan patching

  • Security Configuration Assessment with policies based on CIS Benchmarks

  • Adapt or write SCA policies to match the organisation's own standards

  • Lab: assess and harden a Linux machine based on its SCA results

Section 10: MITRE ATT&CK with Wazuh

  • How MITRE ATT&CK is organised: tactics, techniques and sub-techniques

  • How Wazuh maps rules to ATT&CK techniques

  • Use the ATT&CK dashboard to see which techniques appear in the organisation

  • Add MITRE IDs to your own custom rules

  • Lab: find gaps in detection coverage using the ATT&CK matrix

Day 3 Incident Response and the SOC in Practice

Section 11: Lab: Active Response

  • The idea behind active response and the risks of automated responses

  • Use ready-made scripts, such as blocking an IP address with the firewall

  • Define the conditions, timeout and target machines for an active response

  • Write a simple custom active response script

  • Lab: automatically block an IP address that brute forces SSH

Section 12: Lab: Alerting and Integrations

  • Send email alerts based on rule level and group

  • Connect Wazuh to Slack through its built-in integration

  • Write a custom integration that sends alerts to a chat or ticketing webhook

  • Design alert levels that keep the team from suffering alert fatigue

  • Lab: send important alerts to the SOC team's chat channel

Section 13: Threat Hunting Basics

  • The difference between waiting for alerts and proactively hunting for threats

  • Build hunting hypotheses from MITRE ATT&CK techniques

  • Search for traces in the Wazuh dashboard with queries and visualisations

  • Hunt with IOCs such as hashes, IP addresses and domains

  • Lab: hunt for suspicious PowerShell activity in Sysmon data

Section 14: Lab: Attack Simulation and Incident Response

  • The incident response cycle: preparation, detection, containment, eradication and recovery

  • Simulate a brute force attack and a rogue user account on a lab machine

  • Simulate dropping a malware test file (EICAR) and follow the detection

  • Investigate the incident from its alerts and build an attack timeline

  • Write an incident response playbook for common incidents

Section 15: Workshop: SOC Simulation Capstone

  • Act as the SOC team to detect and analyse a series of attacks staged by the instructor

  • Triage alerts, separate out false positives and assess severity

  • Contain the incident with active response and the measures in the playbook

  • Write an incident report with recommendations to improve detection

  • A checklist for taking Wazuh into production in your organisation

Schedule & training options

For individuals — public rounds

No public rounds are open right now. Join the waiting list and we will contact you first when the next round opens, or ask us on LINE. Or call 02-570-8449 or 088-807-9770

For organisations — in-house / private

  • Tailor the content to your team’s tools and projects
  • Your dates, at your office or live online
  • Quotation with tax ID for procurement
Corporate training quote

Instructors

Frequently asked questions

Who is SOC and SIEM with Wazuh for, and what background is needed?

Built for System and network administrators who are responsible for their organisation's security · Junior SOC analysts and anyone who wants to move into Blue Team work · IT security teams looking for an open source SIEM for their organisation Background you should have: Administrator-level basics on the Linux command line and on Windows · Networking fundamentals such as IP addresses, ports, protocols and DNS Not sure the fit is right? Talk to our team on LINE @itgenius or call 02-570-8449.

How much does SOC and SIEM with Wazuh cost and how long does it run?

THB 9,900 (currently THB 8,910 on promotion). The course runs 18 hours. The price excludes 7% VAT (for payment in a company's name). Pay by bank transfer to the company account, confirm it on our payment page, and we can issue the receipt or tax invoice in your company's name.

Do I get a certificate?

Yes. Everyone who completes the course receives a Certificate of Completion from IT Genius Institute. Each certificate carries its own number, and anyone holding that number can verify it online on our certificate page, so you can add it to your portfolio or pass it to HR as evidence of training.

Where does the training take place, and is there an online option?

You can attend onsite at IT Genius Institute or arrange to join online, and we also run it as a private in-house session for your team. Ask about dates and venues on LINE @itgenius or call 02-570-8449.

What if I fall behind or miss a session — can I retake it?

Yes. You may retake the same course free of charge in a later round, under the institute's conditions. Tell our team which course and round you attended, and we will check it and offer you the rounds that still have seats. Ask us on LINE @itgenius or call 02-570-8449.

How do I enrol, or request a quotation for my company?

Enrol online with the registration form on this page. You can register several attendees at once and enter your tax ID and billing address for the tax invoice. Or request a company quotation straight from the quote button. For anything else call 02-570-8449 or reach us on LINE @itgenius.