Skip to content
Back to skills

Implementing Endpoint Detection With Wazuh

ASecurity

Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing with wazuh-logtest, and automated active-response actions. Use when setting up endpoint detection and response, writing or testing custom Wazuh rules, or querying and triaging Wazuh alerts.

  • 67 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
securitypythongotestingapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills --skill implementing-endpoint-detection-with-wazuh --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Implementing Endpoint Detection With Wazuh?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Implementing Endpoint Detection With Wazuh
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/costrict-plugins-repo-implementing-endpoint-detection-with-wazuh/badge)](https://www.skillsdirectory.com/skills/costrict-plugins-repo-implementing-endpoint-detection-with-wazuh)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: implementing-endpoint-detection-with-wazuh
description: Deploys and configures Wazuh SIEM/XDR for endpoint detection, covering agent authentication and management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, rule testing with wazuh-logtest, and automated active-response actions. Use when setting up endpoint detection and response, writing or testing custom Wazuh rules, or querying and triaging Wazuh alerts.
domain: cybersecurity
subdomain: security-operations
tags:
- siem
- xdr
- wazuh
- endpoint-detection
- custom-rules
- incident-response
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- GOVERN-1.1
- MEASURE-2.7
- MANAGE-3.1
- MANAGE-2.4
- MEASURE-3.1
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1685.002
- T1685.005
---
# Implementing Endpoint Detection with Wazuh

## Overview

Wazuh is an open-source SIEM and XDR platform for endpoint monitoring, threat detection, and compliance. This skill covers managing agents via the Wazuh REST API, creating custom decoders and rules in XML for organization-specific detections, querying alerts, and testing rule logic using the logtest endpoint.


## When to Use

- When deploying or configuring implementing endpoint detection with wazuh capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation

## Prerequisites

- Wazuh Manager 4.x deployed with API enabled
- Python 3.9+ with `requests` library
- API credentials (username/password for JWT authentication)
- Understanding of Wazuh decoder and rule XML syntax

## Steps

### Step 1: Authenticate to Wazuh API
Obtain JWT token via POST to /security/user/authenticate.

### Step 2: List and Monitor Agents
Query agent status, versions, and last keep-alive via /agents endpoint.

### Step 3: Query Security Alerts
Search alerts by rule ID, severity, agent, or time range.

### Step 4: Test Custom Rules with Logtest
Use the /logtest endpoint to validate decoder and rule logic against sample log lines.

## Expected Output

JSON report with agent inventory, alert statistics, rule coverage, and logtest validation results.

Files in this skill

  • LICENSE11 KB
  • SKILL.md2.3 KB
  • references/api-reference.md2 KB
  • scripts/agent.py7.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…