Project Overview – What I Learned
During this project, I learned how to set up and use Wazuh as a SIEM for security monitoring across Windows and Linux systems. I installed Wazuh agents on ad01 and observer and learned how to verify that they were communicating with the Wazuh Manager.
One of the biggest things I learned was how different security tools can work together. Sysmon provided detailed Windows system activity, while Wazuh collected and organized those events so they could be searched and analyzed.
Experiment 1: Apache Log Monitoring
I learned how to monitor Apache web server logs and use SQL injection testing to generate security events. I also worked with custom Wazuh rules and decoders to help identify and process specific activity in the logs.
This showed me that a SIEM is not just about collecting logs. The logs need to be properly decoded and matched against rules so that useful security alerts can be generated.
Experiment 2: Sysmon Setup
I installed Sysmon on the Windows ad01 server and configured the system so that its events could be forwarded to Wazuh. I then checked Wazuh to confirm that the Sysmon events were being received.
This helped me understand how endpoint telemetry can provide much more information than basic Windows logs.
Experiment 3: PowerShell Registry Detection
I also used PowerShell to modify registry values and monitored the activity using Sysmon. The registry changes generated Sysmon Event ID 13, which is associated with registry value modifications.
The activity was mapped to MITRE ATT&CK T1112 – Modify Registry. This helped me understand how an individual Windows event can be connected to a larger attack technique.
Troubleshooting
The project also gave me experience troubleshooting problems instead of simply following instructions. I ran into issues such as syntax errors, missing logs, and Event Viewer warnings. I had to check my configurations, commands, and log sources to determine why the expected events were not appearing.
This taught me that SIEM work involves a lot of testing and troubleshooting. If an event does not appear, it doesn't necessarily mean the attack or command failed—it could mean the logging or forwarding configuration needs to be fixed.
What I Learned Overall
Overall, I learned how to:
Deploy and configure Wazuh agents.
Monitor Windows and Linux systems.
Configure and use Sysmon.
Forward endpoint events into Wazuh.
Monitor Apache logs.
Create and use Wazuh rules and decoders.
Use PowerShell to generate controlled security activity.
Identify Sysmon Event ID 13.
Map events to MITRE ATT&CK T1112.
Use Wazuh Discover to search and filter events.
Troubleshoot missing logs and configuration problems.
Use Atomic Red Team for controlled security testing.
Understand how centralized SIEM monitoring can help identify suspicious activity.
Reflection
The coolest part of the project was seeing a simple action, such as changing a registry value with PowerShell, turn into a Sysmon event that could be collected by Wazuh and mapped to a MITRE ATT&CK technique. It helped connect the different parts of the project together and made the SIEM process easier to understand.
My favorite resources were the Wazuh documentation and MITRE ATT&CK, because they helped me understand both the technical setup and what the security events actually meant.
My advice for future students would be to read the logs carefully and don't assume something is broken just because an event isn't showing up immediately. Check the configuration, test one part at a time, and troubleshoot the problem before moving on.

Top comments (0)