Skip to main content
Back to all walkthroughs
Room Icon

Building Wazuh Rules

Max room.

Learn how to create rules in Wazuh for your environment.

medium

60 min

12

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In the previous room, Exploring , you learned about basic Wazuh concepts: decoders and rules. Out of the box, Wazuh has a comprehensive set of pre-configured rules, but there are still scenarios or risks unique to an organization that these rules may not cover. To compensate for this, organizations can create custom alert rules, which is the focus of this room.

Learning Objectives

  • Learn how important data is extracted from logs using Decoders
  • Learn how alerts are triggered using custom Wazuh Rules
  • Learn how to add new rules to extend detection capabilities
  • Learn how to simulate a real-world attack to test existing rules

Prerequisites

  • If you need a high-level overview of Wazuh features, visit the Exploring Wazuh room
  • Wazuh relies on regex, so brush up by checking out the Regular Expressions room
  • We'll use logs as an example for this room, so consider the Sysmon room

Machine Access

We will interact with the Wazuh dashboard and server installed on a lab machine for this room. Start the lab machine in split-screen view by clicking on the Start Lab Machine button below. Leave the running for 5 minutes for Wazuh to finish setting up, and access the dashboard with these credentials:

  • URL: https://LAB_WEB_URL.p.thmlabs.com:8443
  • Username: thmuser
  • Password: TryHackMe!

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

Open Wazuh and let's continue!