All tools

Defensive / Blue

Wazuh

Open-source XDR/SIEM platform for log analysis and FIM.

intermediate
Linux
Docker
Defense

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Building a free detection stack in a home lab.

How

Deploy manager + agents; create rules; alert on attacks you run.

Why

Purple team feedback loop in your own lab.

Commands & usage

# Use official Docker all-in-one or step-by-step install

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

siem
xdr
blue

Related in Defensive / Blue