Collection of custom Wazuh scripts, integrations, active responses, and utilities to enhance monitoring capabilities.
Author: Adam Pielak (tick) — tick@linuxmafia.pl
wazuh-agent/ — agent configuration and group management scripts
wazuh-manager/ — manager-side: integrations, active responses, wodles, sync
integrations/
active-response/
wodles/
backup/
wazuh-indexer/ — OpenSearch cluster config, ISM policies
wazuh-dashboard/ — Dashboard config, scripted fields
health/ — standalone health check scripts (agent + indexer)
filebeat/ — Filebeat config and pipeline templates
wazuh.blog/ — custom Wazuh rules and decoders from blog articles
rules/ — detection rules organized by platform
decoders/ — log decoders organized by platform
CVE-2025-24016/ — CVE PoC material and detection rules
misc/ — debug one-liners, vendor-specific notes
| File | Description |
|---|---|
add-agent-to-group.sh |
Assign agents to groups based on OS detection |
linux-wazuh-agent-local_internal_options.sh |
Set local_internal_options.conf on Linux agent and restart |
windows-wazuh-agent-local_internal_options.ps1 |
Set local_internal_options.conf on Windows agent and restart |
windows-enable-PSLogging.ps1 |
Enable PowerShell script block and module logging |
wazuh-manager-local_internal_options.conf |
Reference local_internal_options.conf for manager |
| File | Description |
|---|---|
wazuh-agent-health-check.sh |
Per-group agent status table (active/disconnected/never_connected) with pagination |
wazuh-indexer-health.sh |
OpenSearch cluster health, disk usage per node, unassigned shards; exits non-zero for red/disk threshold breach — cron-friendly |
| File | Description |
|---|---|
sync-wazuh-conf.sh |
Sync ossec.conf from master to all workers via cluster_control |
integrations/custom-keep.py |
Wazuh → Keep (alert management) integration; queries OpenSearch for document ID, sends structured alert to Keep webhook |
active-response/suricata_ja3.py |
Active response stub for processing Suricata JA3 data |
wodles/esquery.py |
Periodic Elasticsearch/OpenSearch query wodle; sends event count to Wazuh socket |
| File | Description |
|---|---|
opensearch.yml |
4-node cluster config template |
jvm.options |
JVM heap settings |
wazuh-index_hot_warm_delete-policy.json |
ISM policy: hot (14d) → warm (replica 0, warm-tier node) → delete (102d) — requires a dedicated warm node with node.attr.temp: warm |
ism-wazuh-alerts-retention.json |
ISM policy: delete wazuh-alerts-4.* after 90 days |
ism-security-auditlog-retention.json |
ISM policy: delete security-auditlog-* after 30 days |
ism-wazuh-statistics-retention.json |
ISM policy: delete wazuh-statistics-* after 90 days |
ism-wazuh-monitoring-retention.json |
ISM policy: delete wazuh-monitoring-* after 180 days |
| File | Description |
|---|---|
opensearch_dashboards.yml |
Dashboard config template |
node.options |
Node.js heap settings |
wazuh_flag_scripted_fields.txt |
Scripted field mapping country name → flag emoji |
| File | Description |
|---|---|
filebeat.yml |
Filebeat config for shipping to OpenSearch |
pipeline.json |
Ingest pipeline definition |
wazuh-template.json |
Index template for wazuh-alerts |
Custom Wazuh rules, decoders, integrations, and automation scripts extracted from blog articles. All XML files are validated against Wazuh specifications.
Rules by platform:
rules/linux/— 42 rules (tetragon, AppArmor, credential access, persistence, resource monitoring)rules/windows/— 81 rules (ransomware protection, FIM, event log monitoring)rules/cross-platform/— 750 rules (web attacks, cloud, Kubernetes, malware detection)rules/macos/— 13 rules (system monitoring)rules/kubernetes/— 51 rules (cluster security)rules/cloud/— 36 rules (cloud platform alerts)rules/dns/— 15 rules (DNS monitoring)rules/mongodb/— 23 rules (database security)
Decoders by platform:
decoders/linux/— 15 decoders (tetragon, health metrics)decoders/windows/— 3 decoders (ransomware, FIM)decoders/cross-platform/— 338 decoders (vault audit, sysmon, cloud logs)decoders/macos/— 27 decoders (system events)decoders/kubernetes/— 11 decoders (API server, kubelet)decoders/cloud/— 41 decoders (AWS, Azure, GCP, SaaS)decoders/dns/— 53 decoders (DNS protocols, query types)
Integrations by platform:
integrations/linux/,integrations/windows/,integrations/macos/,integrations/kubernetes/,integrations/cloud/,integrations/dns/,integrations/mongodb/,integrations/cross-platform/— Wazuh integration configuration files for external platforms and services
Automation scripts by platform:
scripts/linux/,scripts/windows/,scripts/macos/,scripts/kubernetes/,scripts/cloud/,scripts/dns/,scripts/mongodb/,scripts/cross-platform/— Bash scripts for deployment, configuration, and automation tasks based on blog tutorials
Wazuh unsafe deserialization RCE — detection and PoC material.
| File | Description |
|---|---|
CVE-2025-24016-exploit.py |
Simple PoC: unhandled_exc deserialization payload for arbitrary command execution |
CVE-2025-24016-exploit2.py |
Extended PoC with banner and argument parsing |
CVE-2025-24016-POC.py |
__reduce__ payload variant |
CVE-2025-24016-POC.curl |
Raw curl PoC for manual testing |
CVE-2025-24016.snort |
Snort + YARA rules for Mirai IOC detection |
nuclei-CVE-2025-24016.yaml |
Nuclei template for safe detection (triggers NameError, no exploitation) |
| File | Description |
|---|---|
debug-wazuh..txt |
tcpdump one-liners for monitoring Wazuh agent traffic (port 1514) |
mikrotik2wazuh.txt |
MikroTik → Wazuh log forwarding notes |
# Agent health (prompts for password if not supplied)
./health/wazuh-agent-health-check.sh https://localhost:55000 wazuh-wui <password>
# Indexer health (default threshold 80%)
./health/wazuh-indexer-health.sh https://localhost:9200 admin <password>
# Custom disk threshold
./health/wazuh-indexer-health.sh https://localhost:9200 admin <password> 75Exit codes for wazuh-indexer-health.sh: 0 = green, 1 = yellow, 2 = red or disk threshold exceeded.
All ISM policies under wazuh-indexer/ism-*.json follow the same pattern: hot → delete with configurable min_index_age. Adjust retention values at the top of each file before deploying.
Create a policy:
curl -sk -u admin:<password> \
-XPUT "https://<indexer>:9200/_plugins/_ism/policies/<policy_id>" \
-H "Content-Type: application/json" \
-d @wazuh-indexer/ism-wazuh-alerts-retention.jsonApply to existing indices (ISM templates only attach to newly created indices automatically):
curl -sk -u admin:<password> \
-XPOST "https://<indexer>:9200/_plugins/_ism/change_policy/wazuh-alerts-4.*" \
-H "Content-Type: application/json" \
--data-raw '{"policy_id": "wazuh-alerts-retention-90d"}'Check policy status on an index:
curl -sk -u admin:<password> \
"https://<indexer>:9200/_plugins/_ism/explain/<index-name>?pretty"Disk planning reference (3-node cluster, no replicas on alerts):
| Retention | ~15 GB/day ingest | Total data | Per-node estimate |
|---|---|---|---|
| 30 days | 450 GB | 450 GB | 150 GB |
| 60 days | 900 GB | 900 GB | 300 GB |
| 90 days | 1.35 TB | 1.35 TB | 450 GB |
OpenSearch default watermarks: low=85%, high=90%, flood=95%. Size your volumes accordingly.
<ossec_config>
<!-- Keep integration -->
<integration>
<name>custom-keep</name>
<hook_url>http://KEEP_IP_ADDRESS:8080/alerts/event</hook_url>
<api_key>KEEP_API_KEY</api_key>
<level>3</level>
<alert_format>json</alert_format>
</integration>
</ossec_config>