implementing-endpoint-detection-with-wazuh

mukul975/implementing-endpoint-detection-with-wazuh · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.0 KB
  • 📁scripts
  • ⚙️agent.py 7.4 KB
  • 📄LICENSE 11.0 KB

Related

  1. implementing-ticketing-system-for-incidents · mukul975 bundle
    Automates incident ticketing by connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured tracking, SLA management, escalation workflows, and compliance documentation.
    24.6k
    repo stars
  2. fleet-hunting-with-velociraptor · mukul975 bundle
    Deploy a Velociraptor server and agents, then write and execute VQL hunts across a fleet of endpoints for threat hunting and incident response.
    24.6k
    repo stars
  3. configuring-suricata-for-network-monitoring · mukul975 bundle
    Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms.
    24.6k
    repo stars
  4. implementing-network-deception-with-honeypots · mukul975 bundle
    Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie to detect unauthorized access, lateral movement, and attacker reconnaissance.
    24.6k
    repo stars
  5. performing-network-traffic-analysis-with-zeek · mukul975 bundle
    Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
    24.6k
    repo stars
  6. detection-engineering-coverage-evaluation · google
    Automates detection engineering workflows in Google SecOps by extracting threat intelligence, generating detection opportunities, simulating attacker behavior with synthetic events, evaluating rule coverage, and creating new YARA-L 2.0 rules to close gaps.
    14.4k
    repo stars

Frequently asked questions

How do I install the implementing-endpoint-detection-with-wazuh skill?

Run npx skillmds add mukul975/implementing-endpoint-detection-with-wazuh in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-endpoint-detection-with-wazuh skill do?

Deploy and configure Wazuh SIEM/XDR for endpoint detection including agent management, custom decoder and rule XML creation, alert querying via the Wazuh REST API, and automated response actions. It is listed under Security, DevOps & Infra, Incident Response, Vulnerability Scanning on SkillMD.

Is implementing-endpoint-detection-with-wazuh safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-endpoint-detection-with-wazuh?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-endpoint-detection-with-wazuh free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-endpoint-detection-with-wazuh?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.