
UpdatedJul 25, 2026
awesome-wazuh — Updated!
🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM
awesome-wazuh 
Curated list of Wazuh resources, tools, and integrations
Wazuh is a free, open-source security monitoring platform for threat prevention, detection, and response.
Contents
- Official Documentation
- Getting Started
- Setup Guides
- Deployment
- Rules & Detection
- Integrations
- Tools & Utilities
- Maintenance
- Compliance
- Training & Certification
- Guides & Tutorials
- Ambassador Program
- Community
- Contributing
Official Documentation
- 🟢 Wazuh Documentation - Installation, configuration, and usage guides
- 🟢 Architecture Overview - System design and components
- 🟢 API Reference - REST API endpoints
- 🟢 Wazuh Blog - Weekly technical articles
- 🟢 Release Notes - Version history and changelog
Getting Started
- 🟢 Installation Guide - Step-by-step deployment instructions
- 🟢 Quickstart - Get running in 30-60 minutes
- 🟢 Wazuh Cloud - Fully managed SaaS option with free tier
- 🟢 Docker Quick Start - Single command deployment for testing
Setup Guides
Step-by-step setup walkthroughs for Wazuh installation, configuration, and operational tasks.
- 🟡 samma-io/wazuh-help - Setup help, troubleshooting, and operational notes for Wazuh deployments
Deployment
Docker
- 🟢 Official Docker Guide - Container deployment documentation
- 🟢 Docker Repository - Docker Compose files and images (1,000+ stars)
Kubernetes
- 🟢 Official Kubernetes Guide - K8s cluster deployment
- 🟢 Helm Charts - Production-grade Helm packages with HA support
Terraform / OpenTofu
- 🟡 Terraform/OpenTofu Provider - Community provider, actively maintained
- 🟡 Terraform Registry - Official Terraform registry entry
- 🟢 Feature Request - Official Wazuh provider (planned)
Ansible
- 🟢 Official Ansible Guide - Multi-host deployment automation
- 🟢 Ansible Playbooks - Ready-to-use playbooks (use release branches for production)
Cloud Platforms
- 🟢 AWS Deployment - CloudTrail, GuardDuty, Security Hub, Macie
- 🟢 Azure Deployment - Log Analytics, Microsoft Graph, Intune
- 🟢 GCP Deployment - Pub/Sub and Cloud Storage integration
- 🟢 Virtual Machines (OVA/AMI) - Pre-built images for quick POC
CI/CD & Testing
- 🟢 Wazuh QA - Automated testing and CI/CD infrastructure
Rules & Detection
- 🟢 Rules Documentation - Rule syntax and optimization
- 🟢 Custom Rules Guide - Writing and testing custom rules
- 🟢 Official Ruleset - Complete rule repository
Community Rules
General-purpose community rule collections.
- 🟡 socfortress/Wazuh-Rules - Community rule collection
- 🟡 Ghost47-coder/Wazuh-Rules - Custom rule set and decoders
Vendor-Specific Rules
Decoders and rulesets for specific devices, appliances, and platforms.
- 🟡 Fortigate Rules & Decoders - Fortigate device monitoring
- 🟡 Pi-hole Decoder & Rules - Pi-hole DNS sinkhole monitoring and detection
- 🟡 Synology DSM (st0rm-cr0w) - Synology DSM decoder and rules
- 🟡 Synology DSM (Tomo-9925) - Alternative Synology DSM decoder implementation
- 🟡 Unifi Decoder - Ubiquiti Unifi network monitoring
Detection Modules
- 🟢 File Integrity Monitoring (FIM) - Detect unauthorized file changes
- 🟢 Vulnerability Detection - CVE scanning and assessment
- 🟢 Configuration Assessment (SCA) - Compliance validation and hardening
- 🟢 Malware Detection - ClamAV and YARA integration
- 🟢 Active Response - Automated threat response
Integrations
Connect Wazuh with external platforms for alerting, ticketing, threat intelligence, and orchestration.
Alerting
- 🟢 Slack - Real-time alerts to Slack channels
- 🟢 PagerDuty - On-call incident escalation
- 🟢 Email - SMTP alert delivery
Ticketing
- 🟢 Generic API Integration - Trigger any external API
- 🟢 ServiceNow Integration - REST API + Python script
- 🟡 Jira Integration - Community guide