Skip to content
Back to skills

Implementing Endpoint Detection With Wazuh

ASecurity

Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.

  • 16 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 9, 2026
ai-agentspythontestingapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 9, 2026

npx -y skills add onfire7777/universal-ai-skills-library --skill implementing-endpoint-detection-with-wazuh --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Implementing Endpoint Detection With Wazuh?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Implementing Endpoint Detection With Wazuh
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/onfire7777-implementing-endpoint-detection-with-wazuh/badge)](https://www.skillsdirectory.com/skills/onfire7777-implementing-endpoint-detection-with-wazuh)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: implementing-endpoint-detection-with-wazuh
license: Apache-2.0
description: Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.
metadata:
  domain: cybersecurity
  subdomain: security-operations
  tags:
  - siem
  - xdr
  - wazuh
  - endpoint-detection
  - custom-rules
  - incident-response
  version: '1.0'
  author: mahipal
---
# Implementing Endpoint Detection with Wazuh

## Overview

Wazuh is an open-source SIEM and XDR platform for endpoint monitoring, threat detection, and compliance. This skill covers managing agents via the Wazuh REST API, creating custom decoders and rules in XML for organization-specific detections, querying alerts, and testing rule logic using the logtest endpoint.


## When to Use

- When deploying or configuring implementing endpoint detection with wazuh capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation

## Prerequisites

- Wazuh Manager 4.x deployed with API enabled
- Python 3.9+ with `requests` library
- API credentials (username/password for JWT authentication)
- Understanding of Wazuh decoder and rule XML syntax

## Steps

### Step 1: Authenticate to Wazuh API
Obtain JWT token via POST to /security/user/authenticate.

### Step 2: List and Monitor Agents
Query agent status, versions, and last keep-alive via /agents endpoint.

### Step 3: Query Security Alerts
Search alerts by rule ID, severity, agent, or time range.

### Step 4: Test Custom Rules with Logtest
Use the /logtest endpoint to validate decoder and rule logic against sample log lines.

## Expected Output

JSON report with agent inventory, alert statistics, rule coverage, and logtest validation results.

Files in this skill

  • LICENSE11 KB
  • SKILL.md1.9 KB
  • references/api-reference.md2 KB
  • scripts/agent.py7.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…