Strengthening Perimeter and Endpoint Infrastructure With Open Source SIEM Platform Wazuh
摘要
This article presents the implementation of a Wazuh SIEM platform at Innotech-EC with the aim of strengthening its security posture through log correlation and integration with a firewall. This project aims to improve the detection and response to security incidents; a mixed methodology was used for its development, bibliographic information from cybersecurity projects was collected, a survey was conducted with the company’s staff, and a GAP vulnerability analysis was performed. Subsequently, a server was installed as the central component along with its agents on the staff’s computers. The collection of agent information was considered for a month, during which the presence of: suspicious malware on the computers, the use of simple passwords to access the Windows operating system, pending updates, and the version of the host operating systems was detected. With these obtained results, it is demonstrated that the implementation of the SIEM has been effective in the evaluation of the infrastructure, the detection of threats, and the fulfillment of the established security objectives.