In this walk through, we will be going through the Wazuh room from Tryhackme. In this room we will learn about Wazuh, which is a free, open source and enterprise-ready security monitoring solution for threat detection and integrity monitoring. So, let’s get started without any delay.
![Tryhackme - Wazuh Wazuh](https://inventyourshit.com/wp-content/uploads/2023/10/Screenshot-from-2023-10-21-14-52-01.png)
Table of Contents
Task 1 – Introduction
Question 1 – When was Wazuh released?
2015
Question 2 – What is the term that Wazuh calls a device that is being monitored for suspicious activity and potential security threats?
Agent
Question 3 – Lastly, what is the term for a device that is responsible for managing these devices?
Manager
![Tryhackme - Wazuh Task 1 - Introduction](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526060053-1024x280.png)
Task 2 – Required: Deploy Wazuh Server
Question 1 – Login to the Wazuh management server on HTTPS://10.10.183.190 before proceeding with this room’s tasks.
Done
![Tryhackme - Wazuh Open Distro for Elasticsearch](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526060623.png)
![Tryhackme - Wazuh Task 2 - Required: Deploy Wazuh Server](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526060734-1024x571.png)
Task 3 – Wazuh Agents
Question 1 – Ensure that you are logged in to the Wazuh management server on HTTPS://10.10.183.190
Done
Question 2 – Navigate to the “Agents” tab by pressing Wazuh -> Agents
Done
![Tryhackme - Wazuh Agents Tab](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061246-1024x547.png)
Question 3 – How many agents does this Wazuh management server manage?
![Tryhackme - Wazuh Wazuh management server manage](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061305.png)
2
Question 4 – What are the status of the agents managed by this Wazuh management server?
![Tryhackme - Wazuh Agent status](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061319.png)
Disconnected
![Tryhackme - Wazuh Task 3 - Wazuh Agents](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061343-1024x370.png)
Task 4 – Wazuh Vulnerability Assessment & Security Events
Question 1 – Ensure that you are logged in to the Wazuh management server on HTTPS://10.10.183.190
Done
Question 2 – Navigate to the Agents tab by pressing Wazuh -> Agents like so
Done
![Tryhackme - Wazuh Wazuh Agents](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061812-1024x567.png)
Question 3 – Select the agent named “AGENT-001“
Done
![Tryhackme - Wazuh Wazuh Agent](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526061846-1024x539.png)
Question 4 – How many “Security Event” alerts have been generated by the agent “AGENT-001”?
Note: You will need to make sure that your time range includes the 11th of March 2022
![Tryhackme - Wazuh Wazuh Security events](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526062544-1024x410.png)
196
![Tryhackme - Wazuh Task 4 - Wazuh Vulnerability Assessment & Security Events](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526062606-1024x411.png)
Task 5 – Wazuh Policy Auditing
Question 1 – Ensure that you are logged in to the Wazuh management server on [10.10.183.190](https://tryhackme.com/room/MACHINE_IP target=)
Done
Question 2 – Navigate to the “Modules” tab by pressing Wazuh -> Modules and open the “Policy Management” module like so:
![Tryhackme - Wazuh Task 4 - Wazuh Policy Auditing](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526062832-1024x447.png)
Done
Task 6 – Monitoring Logons with Wazuh
Question 1 – Ensure that you are logged in to the Wazuh management server on [10.10.229.53](https://tryhackme.com/room/10.10.229.53 target=)
Done
Question 2 – Navigate to the “Management” tab by pressing Wazuh -> Management and open the “Rules” module like so:
Done
![Tryhackme - Wazuh Wazuh Administration](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526063550.png)
![Tryhackme - Wazuh Wazuh Management](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526063625-1024x331.png)
Task 7 – Collecting Windows Logs with Wazuh
Question 1 – What is the name of the tool that we can use to monitor system events?
Sysmon
Question 2 – What standard application on Windows do these system events get recorded to?
Event Viewer
![Tryhackme - Wazuh Task 7 - Collecting Windows Logs with Wazuh](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526064521-1024x217.png)
Task 8 – Collecting Linux Logs with Wazuh
Question 1 – What is the full file path to the rules located on a Wazuh management server?
/var/ossec/ruleset/rules
![Tryhackme - Wazuh Task 8 - Collecting Linux Logs with Wazuh](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526064921-1024x144.png)
Task 9 – Auditing Commands on Linux with Wazuh
Question 1 – What application do we use on Linux to monitor events such as command execution?
auditd
Question 2 – What is the full path & filename for where the aforementioned application stores rules?
/etc/audit/rules.d/audit.rules
![Tryhackme - Wazuh Task 9 - Auditing Commands on Linux with Wazuh](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526065433-1024x218.png)
Task 10 – Wazuh API
Question 1 – What is the name of the standard Linux tool that we can use to make requests to the Wazuh management server?
curl
Question 2 – What HTTP method would we use to retrieve information for a Wazuh management server API?
GET
Question 3 – What HTTP method would we use to perform an action on a Wazuh management server API?
PUT
Question 4 – Navigate to Wazuh’s API console.
Done
Question 5 – Use the API console to find the Wazuh server’s version.
Note: You will need to add the “v” prefix to the number for this answer. For example v1.2.3
v4..2.5
![Tryhackme - Wazuh Task 10 - Wazuh API](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526070935-1024x474.png)
Task 11 – Generating Reports with Wazuh
Question 1 – Use Wazuh’s “Report” feature to generate a report of an agent.
Done
![Tryhackme - Wazuh Wazuh Dashboard](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526071316-1024x542.png)
![Tryhackme - Wazuh Generate report](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526071337.png)
Question 2 – Navigate to the Wazuh “Report” dashboard
Done
![Tryhackme - Wazuh Wazuh Reporting](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526071420-1024x231.png)
Question 3 – Analyse the report. What is the name of the agent that has generated the most alerts?
![Tryhackme - Wazuh Top 5 Agents](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526071655.png)
agent-001
![Tryhackme - Wazuh Task 11 - Generating Reports with Wazuh](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526071717-1024x288.png)
Task 12 – Loading Sample Data
Question 1 – I’ve imported the sample data!
Done
![Tryhackme - Wazuh Wazuh Settings sample data](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526072007-1024x379.png)
![Tryhackme - Wazuh Sample Data](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526072029.png)
Question 2 – I have played around with the sample data.
Done
![Tryhackme - Wazuh Wazuh Sample data](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526072120-1024x445.png)
![Tryhackme - Wazuh Task 12 - Loading Sample Data](https://inventyourshit.com/wp-content/uploads/2023/10/Pasted-image-20230526072149-1024x206.png)
Also Read: Tryhackme – Vulnversity
So that was “Wazuh” for you. In this room, we have learned about the fundamentals of EDR solutions, where an EDR liked Wazuh can be used and then we took a dive into how to access Wazuh. Moving on, we learned how to navigate around Wazuh and create rules and alerts for it. At last, we looked into log digestion in both Windows and Linux environment with Wazuh and had a peek on Wazuh API for further extending its capabilities. On that note, i will take your leave and will see you in next one, Till then “Hack the Planet”.