Wazuh integration

Wazuh threat intelligence integration

Wazuh already collects your logs. Add Q-Feeds and it recognises the malicious IP addresses, domains, URLs and file hashes hidden in them.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and Wazuh integration?

An open source installer puts our indicators of compromise into your Wazuh manager as CDB lists, and adds the decoders and rules that check every event against them. A source or destination IP from the malware list, a domain in your DNS or proxy logs, a malicious URL: each one raises an alert at level 10.

The updater runs from cron and only downloads when your licence has new data, so the manager stays quiet in between. Turn on Active Response and Wazuh blocks a matching IP address on the local firewall as well.

Q-Feeds combines commercial, OSINT and governmental intelligence, refreshed every 20 minutes. Alongside the standard API there is a TAXII 2.1 mode that also delivers file hashes and threat context.

Standard API

Start with the standard API

You only need your API token. The updater pulls the feeds you enable and checks for new data every twenty minutes.

  • Malicious IP addresses, IPv4 and IPv6
  • Malware domains and malicious URLs
TAXII 2.1

Or go further with TAXII

With a TAXII subscription the same installer reads STIX indicators from our TAXII server, including the context that comes with them.

  • MD5, SHA-1 and SHA-256 hashes via Sysmon
  • Category, MITRE ATT&CK and geo data alongside each indicator
Features

What we offer

Always ahead

Intelligence that updates every 20 minutes, so you are always ahead of the attackers.

Automatic response

Trust automated response actions and reduce the manual work needed to stop the latest threats.

Categories

Focus on what matters most, phishing, botnets, dark web and more crafted categories.

Knowledge

Knowledge is power when fighting threats. We take the knowledge part off your hands.

Easy implementation

You never did an implementation this easy. Follow our concise implementation guide and you are good to go.

Fewer false positives

We filter out false positives, so you never waste valuable resources chasing noise.

How it works

Add threat intelligence to Wazuh in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and copy your API token, or use your TAXII credentials.

  2. Run the installer

    Download the scripts from GitHub and run install.sh as root on your Wazuh manager. It asks a handful of questions and does the rest.

  3. Let the rules do their work

    The CDB lists, decoders and rules are installed for you. Wazuh checks every event and raises an alert on a match.

  4. Alert and respond

    Filter on the Q-Feeds rules in Threat Hunting, and switch on Active Response if you want matching IPs blocked automatically.

FAQ

Frequently asked questions about the Wazuh integration

How does Q-Feeds work with Wazuh?

Our indicators are written to CDB lists on the Wazuh manager. The rules that come with the installer compare every decoded event against those lists and raise an alert at level 10 on a match.

Which version of Wazuh do I need?

Wazuh 4.x or later, with root access on the manager. Nothing else has to be installed: the integration uses the Python that ships with Wazuh.

Which indicators can I detect?

Malicious IP addresses and domains through the standard API, plus malicious URLs on Premium. In TAXII mode MD5, SHA-1 and SHA-256 hashes are added, matched against Sysmon events.

Can Wazuh block a malicious IP automatically?

Yes. Active Response is optional during installation. When it is on, Wazuh blocks a matching IP address on the local firewall for a period you set yourself.

Is there a free version?

Yes. The free Community edition lets you test the Wazuh integration before moving to Plus or Premium. The installer itself is open source under the Apache 2.0 licence.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access