I will create custom wazuh rules and threat detection
Cyber Security Analyst, Wazuh SIEM Specialist
About this Gig
Is your Wazuh SIEM installed but missing the security events that matter to you?
I will create, configure, test, and tune custom Wazuh detection rules for your environment.
I specialize in Wazuh SIEM, SOC monitoring, detection engineering, Windows and Linux security events, Sysmon, and MITRE ATT&CK mapping.
What I can build
- Custom Wazuh rules and decoders
- Windows and Linux detections
- Sysmon-based detections
- Brute-force and suspicious PowerShell detection
- Privilege escalation detection
- Malware and IOC detection
- File Integrity Monitoring (FIM) rules
- Authentication and login detections
- MITRE ATT&CK mapping
- False-positive reduction and rule tuning
- Detection testing and documentation
My approach
I review your requirements, configure the detection logic, test rules against relevant events, reduce unnecessary alerts, and provide clear documentation.
Best for
- Existing Wazuh deployments
- SOC and security teams
- Small businesses
- Security engineers
- Labs and homelabs
- Windows/Linux environments
Already have Wazuh installed? Send me your detection requirements before ordering, and I will recommend the right package.
Cloud provider:
Other
Cloud computing resource:
ELK
•
Azure Container Instances
•
Other
My Portfolio
FAQ
Do I need Wazuh already installed?
Yes. This gig is primarily for existing Wazuh installations. For a new deployment, please check my Wazuh deployment gig.
Can you create Windows/Linux detection rules?
Yes. I can create detections for Windows/Linux Security Events, privilege-related activity, system events, Sysmon, PowerShell, authentication activity, and other relevant events.
Can you map detections to MITRE ATT&CK?
Yes. Applicable rules can be mapped to relevant MITRE ATT&CK techniques and tactics.
Can you reduce false positives?
Yes. I can review existing alerts and tune rules to reduce unnecessary or noisy detections.
Can you integrate Sysmon with Wazuh?
Yes. Sysmon-based monitoring and custom detections are available in the Standard and Premium packages.
Can you create a complete SOC detection framework?
Larger detection engineering projects can be handled through a custom offer based on your requirements.
