A full, free, open-source SIEM+XDR: agents on your VMs reporting file integrity, vulnerabilities and MITRE-mapped alerts to a Kibana dashboard. The single best blue-team-lab install.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Easy path: single-node OVA or the one-command Docker stack.
Sysmon on that same VM multiplies visibility 10x.
Attack your own lab and watch yourself get caught โ the core exercise.
Every alert maps to ATT&CK techniques โ learn the framework while defending.
Ransomware's favorite targets, watched in real time.
| Manager | central brain + API |
| Agent | endpoint sensor |
| FIM | file integrity monitoring |
| SCA | config hardening audits |
| Rules/Decoders | detection logic (XML) |
| API | automate everything |
Write one custom rule (docs walk you through) = instant portfolio piece.
Pair Wazuh + MITRE Caldera: run techniques, confirm detections, iterate.
The 'Vulnerabilities' tab does agent-based CVE inventory โ free.
Screenshots of your dashboard with custom rules belong on your resume PDF.
Use Wazuh only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.