you need this FREE CyberSecurity tool

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 พ.ค. 2024
  • The Wazuh Marketplace app was temporarily hidden in Cloud Manager v1.98.0 while they investigate and resolve a critical error resulting in broken deployments. It should be back real soon!
    Deploy Wazuh in the cloud with Linode: ntck.co/linode (Get $100 for 60 days as a new user!!)
    In this video, we discuss the best free cybersecurity tool you need to try: Wazuh. This open-source Security Information and Event Management (SIEM) system is the ultimate tool to help you protect your devices and networks like a cybersecurity expert. We'll show you how to deploy Wazuh, monitor changes to files and the Windows registry, detect unauthorized processes, and more. Plus, we'll discuss the importance of understanding blue team defense and how Wazuh can help you become a cybersecurity expert.
    LINKS:
    ---------------------------------------------------
    -WAZUH OVA INSTALL: documentation.wazuh.com/curre...
    -Wazuh DOCKER Documentation: documentation.wazuh.com/curre...
    -NetworkChuck Windows fundamentals course: ntck.co/windowsfundamentals
    🔥🔥Join the NetworkChuck Academy!: ntck.co/NCAcademy
    **Sponsored by Linode Cloud Computing from Akamai
    SUPPORT NETWORKCHUCK
    ---------------------------------------------------
    ➡️NetworkChuck membership: ntck.co/Premium
    ☕☕ COFFEE and MERCH: ntck.co/coffee
    Check out my new channel: ntck.co/ncclips
    🆘🆘NEED HELP?? Join the Discord Server: / discord
    STUDY WITH ME on Twitch: bit.ly/nc_twitch
    READY TO LEARN??
    ---------------------------------------------------
    -Learn Python: bit.ly/3rzZjzz
    -Get your CCNA: bit.ly/nc-ccna
    FOLLOW ME EVERYWHERE
    ---------------------------------------------------
    Instagram: / networkchuck
    Twitter: / networkchuck
    Facebook: / networkchuck
    Join the Discord server: bit.ly/nc-discord
    0:00 ⏩ Intro
    1:31 ⏩ what do you need??
    2:31 ⏩ Installing Wazuh in the Cloud
    5:11 ⏩ let’s see if our wazuh is ready
    6:23 ⏩ Wazuh Docker Installation
    9:43 ⏩ Adding agents in Wazuh
    13:27 ⏩ secure configuration assessment
    14:39 ⏩ security events
    14:52 ⏩ vulnerabilities
    15:25 ⏩ Windows hosts - integrity monitoring
    16:38 ⏩ FIRST: file monitoring through windows
    20:41 ⏩ changing the interval
    23:06 ⏩ key changes
    23:56 ⏩ SECOND: Actions
    25:06 ⏩ Active response
    27:44 ⏩ Vulnerabilities
    29:13 ⏩ Slack Alerts
    31:29 ⏩ Outro
    AFFILIATES & REFERRALS
    ---------------------------------------------------
    (GEAR I USE...STUFF I RECOMMEND)
    My network gear: geni.us/L6wyIUj
    Amazon Affiliate Store: www.amazon.com/shop/networkchuck
    Buy a Raspberry Pi: geni.us/aBeqAL
    Do you want to know how I draw on the screen?? Go to ntck.co/EpicPen and use code NetworkChuck to get 20% off!!
    fast and reliable unifi in the cloud: hostifi.com/?via=chuck
    Wazuh is an open-source Security Information and Event Management (SIEM) system.
    Wazuh can help protect your devices and networks like a cybersecurity expert.
    This video discusses the best free cybersecurity tool - Wazuh.
    You'll learn how to deploy Wazuh, monitor changes to files and the Windows registry, detect unauthorized processes, and more.
    This video covers the importance of understanding blue team defense and how Wazuh can help you become a cybersecurity expert.
    Wazuh is the ultimate security tool for monitoring changes to files, the Windows registry, and detecting unauthorized processes.
    By deploying Wazuh, you can become a cybersecurity expert and protect your devices and networks from cyber attacks.
    Wazuh uses the Mitre attack framework, compliance, SCA, and security events to help you protect your devices and networks.
    Wazuh's slack integration enables you to stay up-to-date with alerts and active responses.
    #wazuh #cybersecurity #free
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 1.2K

  • @santiago.bassett
    @santiago.bassett 9 หลายเดือนก่อน +2222

    Wazuh founder here. I love the video! Thank you Chuck.
    Currently our team, in collaboration with our users community, is working on improving Wazuh, making it easier to use and more capable. We are motivated to create a quality, free, and open-source alternative to the prevalent commercial solutions. Indeed, we want to help democratize access to these kinds of security products.

    • @leongcheechong1681
      @leongcheechong1681 9 หลายเดือนก่อน +21

      Hi Founder
      Is there any Wazuh certificate good for us ?

    • @ponnurangamh6093
      @ponnurangamh6093 9 หลายเดือนก่อน +26

      Wonderful, Good to know staying Open Source forever and the Community will take care of the rest. Thanks Chuck for making this awesome content.

    • @tygi
      @tygi 9 หลายเดือนก่อน +30

      are you going to make adding a Synology NAS as an agent easy?

    • @FranckEhret
      @FranckEhret 9 หลายเดือนก่อน +13

      Wazuh support is GREAT (even for home lab users), thanks for everything! 👌😉

    • @pavelsimanovsky5622
      @pavelsimanovsky5622 9 หลายเดือนก่อน +10

      One of (if not THE best) tools i ever used.
      so complete, so all-around...Thank you for keeping it open source and free

  • @neerajbabu6643
    @neerajbabu6643 9 หลายเดือนก่อน +756

    We need more self hosted security and blue team content.

    • @NK-iw6rq
      @NK-iw6rq 9 หลายเดือนก่อน +25

      No we don't, we need more red team content ! #EthicalH4ck3rs

    • @Makeitblueagain
      @Makeitblueagain 9 หลายเดือนก่อน

      What

    • @jaap7374
      @jaap7374 9 หลายเดือนก่อน +5

      I would like to learn more about vulnerability scanning and network monitoring.
      I have been playing a bit with OpenVAS, but its not the easiest thing to learn.

    • @vagabond8460
      @vagabond8460 9 หลายเดือนก่อน +29

      People are way too attracted to red team cybersecurity when that’s only a niche corner of a massive industry. Blue team NEEDS the spotlight once in a while

    • @NK-iw6rq
      @NK-iw6rq 9 หลายเดือนก่อน +12

      @@vagabond8460 I am in cyber security, Red Team should definitely be learned by all cyber professionals because nowadays even a blue team analyst needs to be somewhat familiar with pen testing methodologies to understand how an attacker is trying to gain access to data or a system.

  • @obiwan-hf1vp
    @obiwan-hf1vp 9 หลายเดือนก่อน +252

    Security Professional here! Awesome video Chuck!! Any newer security analysts, do this lab and continue to monitor and work with this tool!! If I saw this lab on your resume your application would be at the top. These are real world skills you will use daily working in a Security Operations Center. I have been sending this video to any junior analysts I know. Thank you again Chuck for the great content!! Would love to see more blue team content like this!

    • @yoruasa1
      @yoruasa1 9 หลายเดือนก่อน

      Hey Obiwan! Willing to connect for me to do an informational interview?

    • @Drew-C-
      @Drew-C- 9 หลายเดือนก่อน +9

      Can double confirm. I use overpriced versions of what we saw above (nearly feature-for-feature) in my enterprise work nearly every day. LEARN THIS.

    • @jjann54321
      @jjann54321 9 หลายเดือนก่อน +4

      I agree 100%, if people interested in becoming a sec pro/SOC analyst would stop playing with Kali Linux and spin up a Security Onion VM their time would be much better spent. I understand all the "cool kids" want download TOR (and never use it), hide behind a free VPN and run nmap scans after browsing Shodan but that's just not reality or valuable to anyone.

    • @j5f4
      @j5f4 9 หลายเดือนก่อน +1

      ​@@yoruasa1pp

    • @Gips667
      @Gips667 5 หลายเดือนก่อน

      Thank Chuck for this video, and to you kind sir for great input, I'm transitioning to security field with my 38 years and your comment will help me a lot! Wish me luck!

  • @U_CantTouchThis
    @U_CantTouchThis 8 หลายเดือนก่อน +3

    Thank You Chuck ... :)
    A year ago, when I first saw your channel, you became my inspiration to change my life. I changed my career and since June 2023 I have been working in IT :)
    Great channel keep it up :)
    You're doing a great job!

  • @jjann54321
    @jjann54321 9 หลายเดือนก่อน +79

    Hey Chuck! I know you'll never read this, however, you should try spinning up a Security Onion VM in your internal lab/farm and check it out. Wazuh is just ONE of that many SIEM apps/utilities included. It could make for a lot of quality content if you did a brief "intro/overview" on each of the apps (Playbook, FleetDM, osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, Zeek, and ofc Wazuh). For your followers interested in SOC Analyst/Cybersecurity, this would be a great taste of reality for those perusing that career path. Yes it's open source (free). Just an idea.

    • @NetworkChuck
      @NetworkChuck  9 หลายเดือนก่อน +54

      Adding it to the list !

    • @S60Rguy
      @S60Rguy 9 หลายเดือนก่อน

      @@NetworkChuck Yes please! I was introduced to Security Onion years ago at a local BSides event. This was back when they still used Snort for their IDS. The main issues I saw most users complain about were the amounts of log storage required and the fact that most of today's traffic is encrypted. It's claim to fame has always been its ability to provide contextual data around events, but with everything now using encryption (even DNS queries via settings in modern browsers) I imagine it's ability to peer into network activity has been somewhat diminished. If I'm wrong in assuming this please correct me. Might also be a good topic to address in that video. This video on Wazuh was great though, thanks Chuck!

    • @luce985
      @luce985 9 หลายเดือนก่อน

      ​@@NetworkChuckyour mother will get pregnant by my malware ...

  • @andrewmitchell734
    @andrewmitchell734 9 หลายเดือนก่อน +7

    I utilize Tenable at work, very similar to this. Was looking for a good lightweight home lab alternative and this is very helpful. . . will definitely be tinkering around with this.

  • @sashay404
    @sashay404 8 หลายเดือนก่อน +1

    Always a pleasure to watch your videos! You're so knowledgeable and not condescending. Keep up the good work!

  • @RaymondVegaBoomBoomRay
    @RaymondVegaBoomBoomRay 9 หลายเดือนก่อน

    Absolutely enjoyed this video! I setup my own Wazuh Server running on CentOS previously; However, your tutorial has been instrumental on setting up my Wazuh to monitor my environment. The Active Response was something I was not even tracking on previously and can be a huge time saver in configuring your webservers to do exactly what you can do in Wazuh (e.g., blocking logon attempts). Definitely bookmarking this video as I work on that portion and other configurations. Waiting for Wazuh to implement support for running vulnerability scans on Amazon Linux 2023 servers, hopefully I can turn that on soon! Thanks Chuck!

  • @zathrasjr
    @zathrasjr 9 หลายเดือนก่อน +16

    Thank you Chuck! I work for a security company that sells a SIEM product, but my access is very limited, and information is not shared (security people tend to be tight lipped). With Wazuh I can finally try out these concepts without limitations, and learn the terminology so that I'm speaking the same language as the engineers I work with. Wazah will be going on a spare NUC this weekend, so thanks for giving me something to do this weekend!

  • @kukuxumusu82
    @kukuxumusu82 9 หลายเดือนก่อน +21

    Dude, you're the best! As a hardcore dev of over 15 years who ended up moving into business / tech strategy role and then returning to hands-on tech both as a fun hobby as well to fulfill a practical need to remain current with the detail to be effective in my job, your videos and topic range tick all the boxes. You've mastered the art of both providing sufficient depth and explanation at speed so as not frustrate viewers like me that often eyeroll at videos speaking at the "noob" level, while also being equally helpful to those learning for the first time that are noobs. Love the content, depth, pace, and wide range of topics. Keep it up, if you don't have one already, NUMBER ONE FAN, RIGHT HERE!!

  • @servicesrestreamed6407
    @servicesrestreamed6407 8 หลายเดือนก่อน +1

    Hi Chuck. This is probably one of the best you've done yet. Keep up the great work!

  • @raymondfb
    @raymondfb 9 หลายเดือนก่อน

    Thank you Chuck for taking the time to make this video. this is very cool.

  • @marcmedeiros8857
    @marcmedeiros8857 9 หลายเดือนก่อน +21

    As always, great blend of amazing content, information and entertainment. Keep up the great work!

  • @hule8899
    @hule8899 9 หลายเดือนก่อน +139

    Just a hint, instead of manually changing configuration on each host, its better to use shared configuration in the admin console. You can make groups out of agents and apply taht shared config to specific groups. Much easier to do it once than changing for example 200 config files or making script for AD to copy that config file.

    • @NK-iw6rq
      @NK-iw6rq 9 หลายเดือนก่อน

      Great tip!

    • @fernandomendieta5463
      @fernandomendieta5463 9 หลายเดือนก่อน +7

      Maybe another aporoach could be using the Wazhou API and Ansible, in that way you can make invidividual scripts or playbooks for the different os or servers uses, like back, front, middle, database.. each one with specific config

    • @-someone-.
      @-someone-. 9 หลายเดือนก่อน

      Thanks for the tip! Also, do you think a raspberry pi 4b 8gb model would be able to run wazuh?

    • @Anyobservation
      @Anyobservation 9 หลายเดือนก่อน +2

      @@-someone-. I would assume it depends largely on how much data you need to process. As long as there are no dependency issues, it should be able to handle small scale monitoring.

    • @-someone-.
      @-someone-. 9 หลายเดือนก่อน

      @@Anyobservation i tested it out, and it’s ok, but elastic siem (running on kali purple) actually worked faster.

  • @TorCrypt1c_4740
    @TorCrypt1c_4740 9 หลายเดือนก่อน +1

    I needed this 2 weeks ago. Thanks for the vid and can't wait to stand this up!

  • @theodoros_1234
    @theodoros_1234 9 หลายเดือนก่อน

    This is incredibly useful, thank you for making a video about this! I'll make sure to install this on my server tomorrow.

  • @nunomoreira4678
    @nunomoreira4678 9 หลายเดือนก่อน +18

    Security Engineer here, great content on this video.
    I've been working with wazuh for quite some time now, and it's amazing how you can create your own rules, decoders, and custom integrations.
    Wazuh is a beast once you dedicate the time

    • @NatureBD0001
      @NatureBD0001 3 หลายเดือนก่อน +1

      i need your assist! Help me if you can!

  • @TravisHershberger
    @TravisHershberger 9 หลายเดือนก่อน +7

    If you're only monitoring a small number of client systems, the $5/month Linode should work just fine. However, you have to create and mount additional swap space (swapfile in this case is easiest). Obviously not recommended for a production environment, but works fine for a home lab.

  • @AstralRaver
    @AstralRaver 3 หลายเดือนก่อน +1

    Installation went perfectly fine and what a useful tool indeed! Thank you. I have to add that your channel is great and very practically useful so please keep up the good job.

  • @MrJulianogiudice
    @MrJulianogiudice 5 หลายเดือนก่อน

    I've started to follow you a week ago and I really enjoy your videos, including this one! Thanks a lot to bring us some information about security as well as a great tool like Wazuh, great job Chuck!

  • @carlorivas7653
    @carlorivas7653 9 หลายเดือนก่อน +13

    Thanks man! I have several tools at work comparable to Wazuh, but I was looking for a vulnerability scanner... this looks great! I appreciate the time you're taking to research and prepare these kind of videos. Keep it up!

  • @jackrobb1609
    @jackrobb1609 9 หลายเดือนก่อน +14

    Hey Chuck, great video!! For those folks who do not have time to maintain a SIEM, how would you compare Wazuh to something like Blumira??

  • @rangefreewords
    @rangefreewords 9 หลายเดือนก่อน

    The coffee and personal cam video editing for audio coherence is top notch. ALVIIIN!!!

  • @therealcaptainzaydenx
    @therealcaptainzaydenx 8 หลายเดือนก่อน

    Great Tool Chuck! Thanks for the new knowledge for this Wazuh. I will try this right now and have some tinkering on it. thanks again!

  • @ayseertas3434
    @ayseertas3434 9 หลายเดือนก่อน +271

    Hey *Metaspyclub* what an amazing work this has been and with all the crazy detection that you guys make possible. You guys take hacking to a whole new level and get the job done ASAP!!! I'm wondering what are all your personal qualifications?I don't think that it was ever mentioned before.

  • @user-wz7pw7sp7r
    @user-wz7pw7sp7r 5 หลายเดือนก่อน +1

    Dude, I have to say, you never fail me bro. It doesnt matter what cyber question i have, you have a video for it. I found this one in a frantic rush to find a SIEM i could use for a proof of concept for the course I am studying and it was AMAZING! Easy to set up thanks to your walkthrough but also the run down on config, so helpful and will be so good to learn the ins and outs of blue team and defense. So, thank you mate, really appreciate your work!

  • @Wahinies
    @Wahinies 7 หลายเดือนก่อน

    Thank you for sharing your ideas on top of the primary subject matter along with your humor and charm. I feel like your videos help with memory retention just because they are so fun to watch

  • @Sladeofdark
    @Sladeofdark 9 หลายเดือนก่อน +9

    It is great to see OSSEC still doing great things. this is the tool (Security Onion suite) that I got my real start with 10 years ago, and I STILL highly recommend the same stack because I have not seen an agent that does what the ossec agent does with the level of simplicity of setup. Man this makes me want to return to Security form Devops :) Thanks as always Chuck!

  • @Synclon
    @Synclon 9 หลายเดือนก่อน +38

    Chuck look like my Grandpa wearing those glasses 😂

    • @nerdbird8715
      @nerdbird8715 9 หลายเดือนก่อน +1

      Your gramps is a baddie

    • @conm9891
      @conm9891 9 หลายเดือนก่อน

      Hopefully your grandpa wasnt brainwashed by a group of pedophiles in robes pushing their own agenda. Hopefully your grandpa is educated and doesnt believe in these fairy tales of bullshit known as religion.

    • @tomlocast2964
      @tomlocast2964 9 หลายเดือนก่อน +2

      The loyal subscribers of Network Chuck must be cautious and mindful of any potential issues that may arise regarding his honesty and integrity in providing services.

    • @nostalgicnow6001
      @nostalgicnow6001 2 หลายเดือนก่อน

      😂😂😂

  • @mandy.coralde
    @mandy.coralde 8 หลายเดือนก่อน

    this is a very informative video. Can't wait to have my own wazuh installed and running. thanks Chuck. More power.

  • @camilomartinez8727
    @camilomartinez8727 9 หลายเดือนก่อน

    I was thiking in what to do either Ossec or wazuh. After this I'm setting wazuh for sure. Great video.

  • @SonOfJoy
    @SonOfJoy 9 หลายเดือนก่อน +17

    Everytime you say Wazuh, it makes me think about that term "WAAAAAZUP!!" I'm currently attending a Cyber Security School and I just went through a module that taught about this application. Thanks for setting it up Chuck. Knowledge can't be used unless its applied to a real world scenario.

    • @sriharshareddy2291
      @sriharshareddy2291 8 หลายเดือนก่อน

      Hey, I am planning to start my career in cybersecurity, I am experienced in devops and linux background for 13 years. Please let me know the directions or places where people discuss basics and please help me on that. @SonofJoy or @NetworkChunck

  • @jaytboricua12
    @jaytboricua12 9 หลายเดือนก่อน +6

    That was an excellent tutorial. Have watched multiple Wazuh deployment videos and none of the ones I watched went into this much detail. I am not big into deploying anything on cloud infrastructure but I can see myself using all of the techniques you demonstrated. I would love to see the same level of tutorial for deploying Security Onion. Great job and thanks for so much knowledge shared over the years.

  • @lerooxx
    @lerooxx 9 หลายเดือนก่อน

    Normally I don't watch such long videos, but this one was watched from beginning until end ;-) Thanks for it!

  • @therealbano2368
    @therealbano2368 9 หลายเดือนก่อน

    Chuck, I absolutely love your content and the way you teach! A major part of why I decided to pursue cybersecurity myself. Now as to this video, can you share how you’d configure wazuh to work with MacOS the way you showed it with windows?

  • @Arville27
    @Arville27 9 หลายเดือนก่อน +9

    Great addition to my home lab, thank you

  • @alexmason7393
    @alexmason7393 8 หลายเดือนก่อน +1

    This actually pretty good solution for SIEM monitoring because we have multiple Windows BI tools environment in Azure, and sometimes we need to know what the developer did to fix the issue on prod and non-prod so the next guy shouldn't have any problem tracking down what the previous guy were doing to fix the issue

  • @johnlegend1360
    @johnlegend1360 9 หลายเดือนก่อน

    Thanks Chuck!! Love your vids! Been away for a bit. Eventually though, I will be jumping into some things, such as installing my pf sense. Once I get into it I will binge your videos. Priceless TH-cam tech info. Thanks a lot!

  • @AndrewSelkirkEh
    @AndrewSelkirkEh 9 หลายเดือนก่อน +5

    Senior dev lead for one of the Gartner SIEM vendor's here for the past 25 years. We always pronounced it "SIM" internally, but ya, it is also called "SEEM" in the industry.

  • @Angry.Canuck
    @Angry.Canuck 9 หลายเดือนก่อน

    Thank you very much for these precious videos you make available for the public! You got a new subscriber.

  • @thehalf8
    @thehalf8 9 หลายเดือนก่อน

    Thanks for this. Love this tool. Really amazing.

  • @jonathanspangler1
    @jonathanspangler1 9 หลายเดือนก่อน +20

    Hey Chuck, I know chances of you reading this are pretty slim. However, I wanted to stop by and pay my respects. Because of you and your videos I was able to pull myself of a very dark place. After long hours and hard work, I passed the security + today. Thank you for the videos.

  • @Viking8888
    @Viking8888 9 หลายเดือนก่อน

    DUDE! This was awesome! Thank you for going through this. I know several people that are going to love this!

  • @jamesmackeysr.4811
    @jamesmackeysr.4811 9 หลายเดือนก่อน

    Dope! Thanks for the tool and demo!

  • @NetworkChuck
    @NetworkChuck  9 หลายเดือนก่อน +138

    The Wazuh Marketplace app was temporarily hidden in Cloud Manager v1.98.0 while they investigate and resolve a critical error resulting in broken deployments. It should be back real soon!
    Deploy Wazuh in the cloud with Linode: ntck.co/linode (Get $100 for 60 days as a new user!!)
    In this video, we discuss the best free cybersecurity tool you need to try: Wazuh. This open-source Security Information and Event Management (SIEM) system is the ultimate tool to help you protect your devices and networks like a cybersecurity expert. We'll show you how to deploy Wazuh, monitor changes to files and the Windows registry, detect unauthorized processes, and more. Plus, we'll discuss the importance of understanding blue team defense and how Wazuh can help you become a cybersecurity expert.
    LINKS:
    ---------------------------------------------------
    -WAZUH OVA INSTALL: documentation.wazuh.com/current/deployment-options/virtual-machine/virtual-machine.html?highlight=ova
    -Wazuh DOCKER Documentation: documentation.wazuh.com/current/deployment-options/docker/wazuh-container.html
    -NetworkChuck Windows fundamentals course: ntck.co/windowsfundamentals
    0:00 ⏩ Intro
    1:31 ⏩ what do you need??
    2:31 ⏩ Installing Wazuh in the Cloud
    5:11 ⏩ let’s see if our wazuh is ready
    6:23 ⏩ Wazuh Docker Installation
    9:43 ⏩ Adding agents in Wazuh
    13:27 ⏩ secure configuration assessment
    14:39 ⏩ security events
    14:52 ⏩ vulnerabilities
    15:25 ⏩ Windows hosts - integrity monitoring
    16:38 ⏩ FIRST: file monitoring through windows
    20:41 ⏩ changing the interval
    23:06 ⏩ key changes
    23:56 ⏩ SECOND: Actions
    25:06 ⏩ Active response
    27:44 ⏩ Vulnerabilities
    29:13 ⏩ Slack Alerts
    31:29 ⏩ Outro

    • @adammiller9114
      @adammiller9114 9 หลายเดือนก่อน

      This is AWESOME!!! I've been looking for a great SEIM. Thank you for the video.

    • @cwasonfauna
      @cwasonfauna 9 หลายเดือนก่อน

      Don't forget to change admin password... also bot mitigation on YT be slackin like a mfker

    • @eightbitoni
      @eightbitoni 9 หลายเดือนก่อน

      I would love to see more blue teaming, maybe next you can do sysinternals, great video

    • @FinancewithXibaobao
      @FinancewithXibaobao 9 หลายเดือนก่อน

      Got a System error 2 after doing NET START WazuhSvc

    • @tomlocast2964
      @tomlocast2964 9 หลายเดือนก่อน

      It is crucial for the loyal subscribers of Network Chuck to be vigilant and aware of any potential concerns related to his honesty and integrity when it comes to delivering services.

  • @hisoka44444444
    @hisoka44444444 9 หลายเดือนก่อน

    You weren't kidding, extremely cool stuff, I'm for sure going to set this up this weekend or the next.

  • @KenPryor
    @KenPryor 6 หลายเดือนก่อน

    Excellent video. I recently setup a Wazuh server at home and have several clients, both physical and virtual. It's remarkably easy to setup and so powerful. I still have much to learn and you taught me a few things in this video.

  • @wolverine3030
    @wolverine3030 6 หลายเดือนก่อน +9

    As a cybersecurity content creator, it's essential to emphasize the significance of free and open-source solutions, while also raising awareness about the potential risks they may pose to your data and network security if not managed properly.

  • @bryanmontgomery610
    @bryanmontgomery610 9 หลายเดือนก่อน +3

    This is awesome chuck! One thing I need a follow up on is how in the hell do you change the default login password? The Documentation on this is not very clear at all. Also why do they include a password "Change" option if it does not work. lol

    • @Pray4Tre
      @Pray4Tre 7 หลายเดือนก่อน

      Ran into this same thing, this should not be so difficult

    • @Steven_nevetS
      @Steven_nevetS 7 หลายเดือนก่อน

      Same question?! Did you come right?

  • @15_FPS14
    @15_FPS14 9 หลายเดือนก่อน +116

    ANNM1T is my safety asset along with tether so i'm really glad to hear all this!! thank you very much

  • @cybersamurai99
    @cybersamurai99 9 หลายเดือนก่อน

    I love your videos bro, freaking awesome every single one of them!! - Im deploying this tonight thank brother, I am starting a cyber analyst job in two weeks, and your videos have helped me gain amazing skills over this last year

  • @lesanikuniku2153
    @lesanikuniku2153 9 หลายเดือนก่อน +6

    Is it better than logrythm, arcsight, elastic/elk, splunk?

  • @onemoresmartone
    @onemoresmartone 9 หลายเดือนก่อน +4

    How much data is Wazuh collecting on their "free customers"??

    • @keylanoslokj1806
      @keylanoslokj1806 9 หลายเดือนก่อน +1

      Plenty

    • @bioman2007
      @bioman2007 9 หลายเดือนก่อน +3

      Wazuh cluster spin up a local db and stores the data there. You can take a look at the code. That's the beauty of open source :)

    • @tomlocast2964
      @tomlocast2964 9 หลายเดือนก่อน

      It is crucial for the loyal subscribers of Network Chuck to be vigilant and aware of any potential concerns related to his honesty and integrity when it comes to delivering services.

  • @markus_265
    @markus_265 8 หลายเดือนก่อน

    Great video, started to deploy wazuh in our company and been blown away so far.
    Is it possible to configure active response actions on windows hosts as well or maybe even to trigger active response on other software (EDR/XDR) through an API connection?

  • @datboyblu3
    @datboyblu3 9 หลายเดือนก่อน

    This is awesome!! I just got done playing around with it for about 15 hours! I used their documentation to integrate nmap scans into the manager. Unfortunately, no luck yet. I'm gonna go sleep now lol

  • @Lafiro
    @Lafiro 9 หลายเดือนก่อน

    As always @NetworkChuck this is awesome. Thank you for this. I will be testing this soon and then deploying it to all my virtual machines and client desktops that I manage.
    One thing I may suggest though and I will try to see if it works in this case; no punching a port through the firewall and instead using Cloudflare tunnel to access everything that is needed. Now if this works, it will be even more secure and no machine will be connecting back to the real server location. This is of course only good for those doing on-prem installs.

  • @Pyramid333
    @Pyramid333 9 หลายเดือนก่อน

    Great educational video! Also, in general your content is brilliant.

  • @PaulMisner
    @PaulMisner 9 หลายเดือนก่อน +1

    I've had great experiences working with Wazuh. I thought it was interesting that you referred to it as a SIEM, which is correct, but I've always (or at least for the past couple of years) as XDR or EDR. The agent is so good and you can do so much with it. Security Onion includes this as one of the agents they work with, but I was so impressed with the web GUI native to Wazuh, I chose to just use that. Thanks again Chuck for adding to my home lab todo list.

    • @supremeicecreme1658
      @supremeicecreme1658 9 หลายเดือนก่อน

      It does have both SIEM and XDR which are two separate things. From what I've just been reading, it does seem to blur the lines of the two a bit.

  • @santiagosurt-li9zx
    @santiagosurt-li9zx 9 หลายเดือนก่อน

    Man i was just planning on deploying wazuh and practice using it to get a job in wazuh lol this video comes in the perfect time

  • @MrRyanMonroe
    @MrRyanMonroe 9 หลายเดือนก่อน +1

    YES!!! Thanks chuck. I've been looking for something like this. ❤

  • @ohokcool
    @ohokcool 16 วันที่ผ่านมา

    Dude good looks! I set the indexer, server, and manager up in WSL2 then installed the client in my win11 host and enabled vulnerability detection which was able to find 2 critical vulnerabilities in my system including one that was arbitrary code execution!! You may have saved my homelab. I’m now vulnerability free

  • @user-qy6xr2ju4i
    @user-qy6xr2ju4i 6 หลายเดือนก่อน

    Shout out from Dallas, buddy! Awesome videos!

  • @user-zo9vo3pu5h
    @user-zo9vo3pu5h 8 หลายเดือนก่อน

    It was fantastic. Cannot wait to stand up the wazuh server for my 200+ server environments. Hopefully it will not scare me with millions of vulnerabilities.... Thank you Chuck!

  • @scottuch3576
    @scottuch3576 9 หลายเดือนก่อน

    After just watching your video i I have implemented the wazuh on my organisation
    Thankyou bro
    Do more videos on free open source tools

  • @charlesvanhorn53
    @charlesvanhorn53 7 หลายเดือนก่อน

    Chuck you're the best. I don't even have words to express how grateful I am for all that you do in helping tech nerds like myself.

  • @blaxbrian6877
    @blaxbrian6877 8 หลายเดือนก่อน

    This is awesome, I needed to learn this

  • @Angelizius
    @Angelizius 9 หลายเดือนก่อน

    Hell yes, you did it! :P I started with Wazuh two years ago and implemented it in my business. Currently, I'm using the default Wazuh ruleset, and I've written around 200,000 rules, I guess. But anyway, getting alerts is a nice-to-have, and not logging everything is the best you can do. However, the almighty kill feature is the FIM Module and the active response.
    The Active Response will handle the firewall drop and block brute force attempts by itself. I configured the FIM module on a folder, let's say /root/fim_auto_ansible, and there is a cronjob that downloads the new version of auditd/rules.d daily. The FIM will only trigger the alert when the File-SHA is different. With a local_rule, you can trigger an ansible-playbook command that copies the new rule.d file to all servers and shows you the changes on the Wazuh dashboard in the alert log.
    I enjoy experimenting with some exciting configurations and rebuilding some stuff. I use OpenSearch to send the logs from the Wazuh-manager, first with Fluent-bit to Graylog in a JSON format. If you are using Wazuh with different tools and operating systems, you need to normalize the fields from a log to get better and faster searches.
    But this is really a deep dive into it. Keep up the great work!

  • @fl2rms
    @fl2rms 9 หลายเดือนก่อน

    Thanks, Chuck, i started using this in January this year. It's very good.

  • @tmiles003
    @tmiles003 9 หลายเดือนก่อน

    Awesome tutorial , love the energy and excitement you bring to teaching. Student for Life!

  • @user-si1im1cj1s
    @user-si1im1cj1s หลายเดือนก่อน

    duuude! Love your vids, man! absolutely share your excitement in this stuff! Learning a ton!

  • @delugedj
    @delugedj 9 หลายเดือนก่อน

    Chuck, just want to say thanks man, you make it fun to do tech learnings. Got my pfsense inspiration from you sir. Flat has never been so tight. My inner sys admin is telling me I need this 🤓 first step is lidarr though need me some lossless asap 😅

  • @sasookay514
    @sasookay514 9 หลายเดือนก่อน

    exactly what ive been looking for. thank you for telling us about this.

  • @kholius7445
    @kholius7445 9 หลายเดือนก่อน

    A good video, as always!
    this bundle of SIEM is really interesstng to learn compared to other solutions, cause usually we have to manage agents, an ETL, a distributed DB and a Dashboard to deplay and answer.
    Here it looks like an All In One solution.
    I gonna start by this SIEM before an ELK Stack :)
    What if i need to mutate my data or just act on to segregate datas?

  • @dazzypops
    @dazzypops 9 หลายเดือนก่อน

    Meant in the best possible way - this was not siemless.
    Such a powerful tool! I think it was near the end when you said you'd ask a couple of people to block the ip of the nefarious person trying to log in - could this be done in the Wazuh config too I wonder, so that it's pretty much all automated?

  • @zMurdaaa
    @zMurdaaa 9 หลายเดือนก่อน

    Amazing as always my guy. I deeply appreciate the guidance and knowledge. Blue team all day!

  • @adrianzatorski9486
    @adrianzatorski9486 8 หลายเดือนก่อน

    really COOL tutorial! Thanks Chuck! 👍

  • @pedrovieira4313
    @pedrovieira4313 9 หลายเดือนก่อน

    This is great, would you recommend using this for a small buisness with around 50 endpoints and two servers? I manage a companies network and was looking for a way to better monitor network accessibility, etc.

  • @bluxombie
    @bluxombie 5 หลายเดือนก่อน

    As an elastic engineer, it is nice to see the many ways our stuff is used. Good job, Wazuh.

  • @chichicoolzm1852
    @chichicoolzm1852 9 หลายเดือนก่อน

    Thank you very much I've been really learning a lot from your channel as a Computer engineering student 😊Zambia here😅

  • @theldun1
    @theldun1 9 หลายเดือนก่อน

    Dude, you are so much fun. Wish i had known you when i was growing up learning programing. I would have stuck with it.

  • @user-hx6it3mm9b
    @user-hx6it3mm9b 9 หลายเดือนก่อน

    I've heard about it but didn't know it was so powerful. thanks, a lot

  • @LRaptor99
    @LRaptor99 9 หลายเดือนก่อน

    This is exactly what I was looking for. Thanks

  • @siriondb
    @siriondb 9 หลายเดือนก่อน

    Good stuff. Wazuh has been popping off lately and that is definitely something nice to see!

  • @t4ir1
    @t4ir1 5 หลายเดือนก่อน

    Dude I love your videos. Big fan!
    Thanks for all the help these past months in setting up my home lab!

  • @deanballito
    @deanballito 9 หลายเดือนก่อน

    100x Thumbs up! You're my hero! I have been looking for a tool like this.

  • @poormillionaires6750
    @poormillionaires6750 7 หลายเดือนก่อน +1

    I have been watching your content since I was in grade 6 and to be honest you've played a mojor role in my wellbeing in this crazy tech world...your content is really amazing 💯

  • @jakejimstone5029
    @jakejimstone5029 9 หลายเดือนก่อน

    Great stuff! I did HP Arcsight /w CORR engine. Have you run a video on 'debuggers' for buffer overflow exploits?

  • @samerkabalan8571
    @samerkabalan8571 9 หลายเดือนก่อน

    That's was awesome dude
    Thank you for all explanation
    I will deploy it in my environment

  • @k1lldash9
    @k1lldash9 9 หลายเดือนก่อน

    I went and bought a simple 200 dollar HP refurbish to run this, in order to watch my Windows and Linux machines, this is truly a great product! Setup was a cake walk, I went Docker so I could keep on prem, but what a great addition to a home lab!

  • @lonelygoner2012
    @lonelygoner2012 7 หลายเดือนก่อน

    awesome video. keep them coming.

  • @creeps3289
    @creeps3289 9 หลายเดือนก่อน

    Thanks Chuck you always are full of surprises and good one at that :)

  • @sandeepshah1753
    @sandeepshah1753 3 หลายเดือนก่อน +1

    It was amazing. Very very useful. Me and my son have learned many many technical things from your TH-cam channel. Thanks a lot. This tool I have started using in windows environment. I want to do it on virtual machine. OVA .

  • @RICK_MCN
    @RICK_MCN 4 หลายเดือนก่อน

    Chuck you videos are so enjoyable it's crazy. Your energy is so crazy good makes me wish I could havey PC!!! I have a PC just can't use it atm.

  • @staticninja
    @staticninja 9 หลายเดือนก่อน

    Love the effort and can’t wait to dig into i
    This!

  • @tommykelly8920
    @tommykelly8920 4 หลายเดือนก่อน

    Amazingly clear, concise and easy to follow. Thank you!

  • @RickyGotskills
    @RickyGotskills 8 หลายเดือนก่อน

    I haven't been so hyped to install a new machine in a looooong time! Time to drag out a dust-gathering desktop PC and start playing!

  • @jcbenge08
    @jcbenge08 9 หลายเดือนก่อน

    This is so cool!!! I'll definitely be deploying this soon!!

  • @dan_k1992
    @dan_k1992 9 หลายเดือนก่อน

    Thanks for the great video - one think i was kind of hoping you'd cover is how to monitor your wazuh server itself? Is it the same steps adding as an agent with the address being localhost?

  • @mohsinmalique9777
    @mohsinmalique9777 9 หลายเดือนก่อน

    wow this is amazing!!! please do more shaky video effects when you're drinking coffee. my kids love it.. actually i do too!

  •  9 หลายเดือนก่อน

    I love these videos! I can feel the excitement every time NtChuck gets excited. hahaha