Part 2: Threat Intelligence, Automation, Incident Response, and Threat Hunting
In this part, you will learn how to extend the Wazuh threat intelligence capability by integrating the MISP platform. You will learn to integrate TheHive with Wazuh and MISP to perform threat analysis. In addition to that, you will learn how to automate security operations and management of the Wazuh platform using the security orchestration, automation, and response (SOAR) tool, Shuffle. You will also learn to perform automated incident responses using a Wazuh-native feature called Active Response such as blocking brute force attempts and automatically isolating infected machines. Lastly, we will learn how to leverage the Wazuh platform to conduct proactive threat hunting.
This part includes the following chapters:
- Chapter 3, Threat Intelligence and Analysis
- Chapter 4, Security Automation and Orchestration Using Shuffle
- Chapter 5: Incident Response with Wazuh
- Chapter 6: Threat...