DEV Community

Zehra Begum
Zehra Begum

Posted on

Ox2A Security Blog

Testing Windows Defender and Wazuh with Atomic Red Team
Posted on septemper, 28 by Zehra Begum

  1. Introduction

Building my first SIEM deployment hands-on cybersecurity journey with log aggregation, network visibility, and threat detection. I cover how I stood up and modified a baseline SIEM environment, encountered a few real-world misconfigurations along the way, and ran attack commands using Atomic Red Team (ART) to see how those activities surfaced in our logs.

Whoami

My name is a Zehra Begum, and i am field to specialize in network security and threat detection. This post represents my very first contribution to the cybersecurity community—I hope sharing my process, mistakes, and findings helps other aspiring analysts on a similar path!

  1. Setup

Configured log shipping agents and adjusted system files (e.g., modifying /etc/rsyslog.conf or agent config files) to capture enhanced host and network telemetry.


  1. Experiment time!

Experiment #1 T1053.005:Scheduled Task 

               Test SIEM detection against persistence techniques T1053.005. Running command Atomic tests on Ad01 verifies events trigger expected alert rules in Wazuh.

![[Pasted image 20260928221650.png]]

Experiment #2 T1027: Obfuscated Files or Information

      Registry modification detection (Sysmon Event ID 1 & Event ID 13 When altering Windows registry keys.

Experiment #3 T1078: Valid Account
Test SIEM detection against persistence and privilege abuse techniques using T1078 (Valid Accounts). This experiment verifies whether administrative or newly created account logons, privilege escalations, or account modifications trigger the expected detection rules and alerts in Wazuh.

  1. Conclusion

Running these experiments highlighted the direct connection between endpoint configuration and SIEM visibility: without proper log verbosity, critical attack vectors remain invisible.

To avoid similar issues:

  1. Always validate configuration syntax and service status before testing log ingestion.

  2. Ensure host-level auditing policies (such as Auditd or Sysmon) are properly enabled to capture process execution and command-line arguments.

    1. Final thoughts Coolest Thing Learned: Seeing raw adversary actions executed via Atomic Red Team instantly transform into structured alerts and structured log fields inside the SIEM dashboard. Don't panic when logs don't show up immediately. Systematically isolate the path from event creation $\rightarrow$ local agent capture $\rightarrow$ network transport $\rightarrow$ SIEM ingestion.

6.Refrences
Wazuh Documentation
Atomic RED Team Work Station
MITRE ATT&CK Techique Reference

Top comments (0)