To access material, start machines and answer questions login.
In the previous room, Exploring , you learned about basic Wazuh concepts: decoders and rules. Out of the box, Wazuh has a comprehensive set of pre-configured rules, but there are still scenarios or risks unique to an organization that these rules may not cover. To compensate for this, organizations can create custom alert rules, which is the focus of this room.
Learning Objectives
- Learn how important data is extracted from logs using Decoders
- Learn how alerts are triggered using custom Wazuh Rules
- Learn how to add new rules to extend detection capabilities
- Learn how to simulate a real-world attack to test existing rules
Prerequisites
- If you need a high-level overview of Wazuh features, visit the Exploring Wazuh room
- Wazuh relies on regex, so brush up by checking out the Regular Expressions room
- We'll use logs as an example for this room, so consider the Sysmon room
Machine Access
We will interact with the Wazuh dashboard and server installed on a lab machine for this room. Start the lab machine in split-screen view by clicking on the Start Lab Machine button below. Leave the running for 5 minutes for Wazuh to finish setting up, and access the dashboard with these credentials:
- URL:
https://LAB_WEB_URL.p.thmlabs.com:8443 - Username:
thmuser - Password:
TryHackMe!
Set up your virtual environment
Open Wazuh and let's continue!
Ready to learn Cyber Security?
The Building Wazuh Rules room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in


