CRITICAL INFRA
Loading critical CVEs…
ALL EXPLOITED
Loading…

24/7 SOC with Wazuh SIEM + Suricata IDS

A mature SOC doesn't mean 10 screens and 20 analysts. For SMB / mid-market, a functional 24/7 SOC is built with open-source stack.

Implemented stack

What real "24/7" means

Not people awake 24h. 24/7 automated detection, triage, <15 min human response for P1/P2 via on-call rotation.

Example: install Wazuh + Suricata

A quick start of the detection stack:

# Wazuh all-in-one (server + indexer + dashboard)
curl -sO https://packages.wazuh.com/4.9/wazuh-install.sh
sudo bash wazuh-install.sh -a

# Suricata IDS + ruleset Emerging Threats
sudo apt -y install suricata
sudo suricata-update
sudo systemctl enable --now suricata
sudo tail -f /var/log/suricata/eve.json    # alertele in timp real

Enrolling a Wazuh agent

You add a server/endpoint to Wazuh:

# pe manager: inregistrezi agentul
/var/ossec/bin/manage_agents -a -n web01 -i 10.0.0.11
# pe agent: instalezi + pointezi la manager
curl -sO https://packages.wazuh.com/4.x/wazuh-agent.deb
WAZUH_MANAGER='10.0.0.5' dpkg -i wazuh-agent.deb
systemctl enable --now wazuh-agent

Custom Suricata rule

You add your own rule and update the rulesets:

# /etc/suricata/rules/local.rules
alert http any any -> any any (msg:"Posibil webshell"; content:"cmd="; http_uri; sid:1000001; rev:1;)
suricata-update              # actualizeaza ET Open + local
suricata -T -c /etc/suricata/suricata.yaml   # test config
systemctl restart suricata

Wazuh active response (auto-block)

Wazuh auto-blocks an IP on brute-force:

# /var/ossec/etc/ossec.conf (manager)

  firewall-drop
  local
  5710,5712   
  600

/var/ossec/bin/wazuh-control restart

Suricata inline IPS (nfqueue)

You move Suricata from IDS to IPS that actually drops packets:

# trimiti traficul catre Suricata prin nfqueue
nft add rule inet filter forward queue num 0
# suricata in mod IPS pe coada 0
suricata -q 0 -c /etc/suricata/suricata.yaml
# reguli 'drop' (nu doar 'alert') pt amenintarile confirmate
sed -i 's/^alert/drop/' /etc/suricata/rules/local.rules
Let's discuss your project →