Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyยฉ 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-wazuh โ€” ๐Ÿ›ก๏ธAwesome lists about all kinds of interesting topics of Wazuh XDR/SIEM | Kitploit
Tools/GitHubGitHub/ttlab-research/awesome-wazuh
Vulnerability ScannersConfiguration AuditingMalware AnalysisCloud SecurityDevSecOpsThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseCurated ResourcesLog Analysis
13510142 months agoReviewed by Kitploit
GitHub
ttlab-research/awesome-wazuh

awesome-wazuh

๐Ÿ›ก๏ธAwesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

View RepositoryWebsite

Most Popular

View all โ†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools โ†’
Share

awesome-wazuh Awesome

Curated list of Wazuh resources, tools, and integrations

Wazuh is a free, open-source security monitoring platform for threat prevention, detection, and response.

Contents

  • Official Documentation
  • Getting Started
  • Setup Guides
  • Deployment
    • Docker
    • Kubernetes
    • Terraform / OpenTofu
    • Ansible
    • Cloud Platforms
    • CI/CD & Testing
  • Rules & Detection
    • Community Rules
    • Vendor-Specific Rules
    • Detection Modules
  • Integrations
    • Alerting
    • Ticketing
    • Threat Intelligence
    • Cloud Platforms
    • SOAR
    • Custom Integrations
  • Tools & Utilities
  • Maintenance
    • Backup & Restore
    • Known Issues
  • Compliance
  • Training & Certification
  • Guides & Tutorials
    • AI & LLM Integration
    • Detection & Response
    • General
  • Ambassador Program
  • Community
  • Contributing

Official Documentation

  • ๐ŸŸข Wazuh Documentation - Installation, configuration, and usage guides
  • ๐ŸŸข Architecture Overview - System design and components
  • ๐ŸŸข API Reference - REST API endpoints
  • ๐ŸŸข Wazuh Blog - Weekly technical articles
  • ๐ŸŸข Release Notes - Version history and changelog

Getting Started

  • ๐ŸŸข Installation Guide - Step-by-step deployment instructions
  • ๐ŸŸข Quickstart - Get running in 30-60 minutes
  • ๐ŸŸข Wazuh Cloud - Fully managed SaaS option with free tier
  • ๐ŸŸข Docker Quick Start - Single command deployment for testing

Setup Guides

Step-by-step setup walkthroughs for Wazuh installation, configuration, and operational tasks.

  • ๐ŸŸก samma-io/wazuh-help - Setup help, troubleshooting, and operational notes for Wazuh deployments

Deployment

Docker

  • ๐ŸŸข Official Docker Guide - Container deployment documentation
  • ๐ŸŸข Docker Repository - Docker Compose files and images (1,000+ stars)

Kubernetes

  • ๐ŸŸข Official Kubernetes Guide - K8s cluster deployment
  • ๐ŸŸข Helm Charts - Production-grade Helm packages with HA support

Terraform / OpenTofu

  • ๐ŸŸก Terraform/OpenTofu Provider - Community provider, actively maintained
  • ๐ŸŸก Terraform Registry - Official Terraform registry entry
  • ๐ŸŸข Feature Request - Official Wazuh provider (planned)

Ansible

  • ๐ŸŸข Official Ansible Guide - Multi-host deployment automation
  • ๐ŸŸข Ansible Playbooks - Ready-to-use playbooks (use release branches for production)

Cloud Platforms

  • ๐ŸŸข AWS Deployment - CloudTrail, GuardDuty, Security Hub, Macie
  • ๐ŸŸข Azure Deployment - Log Analytics, Microsoft Graph, Intune
  • ๐ŸŸข GCP Deployment - Pub/Sub and Cloud Storage integration
  • ๐ŸŸข Virtual Machines (OVA/AMI) - Pre-built images for quick POC

CI/CD & Testing

  • ๐ŸŸข Wazuh QA - Automated testing and CI/CD infrastructure

Rules & Detection

  • ๐ŸŸข Rules Documentation - Rule syntax and optimization
  • ๐ŸŸข Custom Rules Guide - Writing and testing custom rules
  • ๐ŸŸข Official Ruleset - Complete rule repository

Community Rules

General-purpose community rule collections.

  • ๐ŸŸก socfortress/Wazuh-Rules - Community rule collection
  • ๐ŸŸก Ghost47-coder/Wazuh-Rules - Custom rule set and decoders

Vendor-Specific Rules

Decoders and rulesets for specific devices, appliances, and platforms.

  • ๐ŸŸก Fortigate Rules & Decoders - Fortigate device monitoring
  • ๐ŸŸก Pi-hole Decoder & Rules - Pi-hole DNS sinkhole monitoring and detection
  • ๐ŸŸก Synology DSM (st0rm-cr0w) - Synology DSM decoder and rules
  • ๐ŸŸก Synology DSM (Tomo-9925) - Alternative Synology DSM decoder implementation
  • ๐ŸŸก Unifi Decoder - Ubiquiti Unifi network monitoring

Detection Modules

  • ๐ŸŸข File Integrity Monitoring (FIM) - Detect unauthorized file changes
  • ๐ŸŸข Vulnerability Detection - CVE scanning and assessment
  • ๐ŸŸข Configuration Assessment (SCA) - Compliance validation and hardening
  • ๐ŸŸข Malware Detection - ClamAV and YARA integration
  • ๐ŸŸข Active Response - Automated threat response

Integrations

Connect Wazuh with external platforms for alerting, ticketing, threat intelligence, and orchestration.

Alerting

  • ๐ŸŸข Slack - Real-time alerts to Slack channels
  • ๐ŸŸข PagerDuty - On-call incident escalation
  • ๐ŸŸข Email - SMTP alert delivery

Ticketing

  • ๐ŸŸข Generic API Integration - Trigger any external API
  • ๐ŸŸข ServiceNow Integration - REST API + Python script
  • ๐ŸŸก Jira Integration - Community guide

Threat Intelligence

Download Tool