Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Threatmapper and Wazuh SIEM integration #2041

Open
whatsinthisbox opened this issue Mar 26, 2024 · 1 comment
Open

Threatmapper and Wazuh SIEM integration #2041

whatsinthisbox opened this issue Mar 26, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned

Comments

@whatsinthisbox
Copy link

Problem:
Existing Wazuh SIEM users lack seamless integration with Threatmapper, hindering efficient correlation and analysis of vulnerability data.

Solution:
Implement native integration between Threatmapper and Wazuh SIEM, allowing automatic ingestion of vulnerability information into Wazuh's indexing platform (e.g., OpenSearch).

Components/Services:

API/Backend

 Deployment/YAMLs

Proposed Workflow:

Threatmapper identifies vulnerabilities across assets (Hosts, Docker images and containers).
Vulnerability data is formatted and ingested into Wazuh SIEM Indexer (Opensearch).
Wazuh indexes and correlates this data with existing security event data.
Security analysts leverage Wazuh's dashboard and querying capabilities for comprehensive threat analysis and response.

Additional Context:
This integration streamlines vulnerability management, enhancing security posture by providing centralized visibility and facilitating prioritized remediation efforts.

@whatsinthisbox whatsinthisbox added enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned labels Mar 26, 2024
@ibreakthecloud ibreakthecloud self-assigned this Mar 27, 2024
@ibreakthecloud
Copy link
Member

@whatsinthisbox ThreatMapper today does not have direct integration with Wazuh, but I do think it can be done using HTTP Endpoint integration if Wazuh has ingestion endpoint available. If that does not work for you, we can always have this issue open until we implement this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned
Projects
None yet
Development

No branches or pull requests

2 participants