Wazuh threat intelligence integration
Wazuh already collects your logs. Add Q-Feeds and it recognises the malicious IP addresses, domains, URLs and file hashes hidden in them.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and Wazuh integration?
An open source installer puts our indicators of compromise into your Wazuh manager as CDB lists, and adds the decoders and rules that check every event against them. A source or destination IP from the malware list, a domain in your DNS or proxy logs, a malicious URL: each one raises an alert at level 10.
The updater runs from cron and only downloads when your licence has new data, so the manager stays quiet in between. Turn on Active Response and Wazuh blocks a matching IP address on the local firewall as well.
Q-Feeds combines commercial, OSINT and governmental intelligence, refreshed every 20 minutes. Alongside the standard API there is a TAXII 2.1 mode that also delivers file hashes and threat context.
Start with the standard API
You only need your API token. The updater pulls the feeds you enable and checks for new data every twenty minutes.
- Malicious IP addresses, IPv4 and IPv6
- Malware domains and malicious URLs
Or go further with TAXII
With a TAXII subscription the same installer reads STIX indicators from our TAXII server, including the context that comes with them.
- MD5, SHA-1 and SHA-256 hashes via Sysmon
- Category, MITRE ATT&CK and geo data alongside each indicator
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
Add threat intelligence to Wazuh in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and copy your API token, or use your TAXII credentials.
Run the installer
Download the scripts from GitHub and run install.sh as root on your Wazuh manager. It asks a handful of questions and does the rest.
Let the rules do their work
The CDB lists, decoders and rules are installed for you. Wazuh checks every event and raises an alert on a match.
Alert and respond
Filter on the Q-Feeds rules in Threat Hunting, and switch on Active Response if you want matching IPs blocked automatically.
Explore other SIEM integrations
Threat intelligence feeds
Curated IP, URL and domain feeds for your whole stack.
Splunk
Without the right threat intelligence, Splunk is just a log server.
TAXII Feeds & Server
TAXII/STIX 2.1 standard, feeds and server software available.
Other SIEMs
Many SIEM vendors support 3rd party threat intelligence.
Frequently asked questions about the Wazuh integration
How does Q-Feeds work with Wazuh?
Our indicators are written to CDB lists on the Wazuh manager. The rules that come with the installer compare every decoded event against those lists and raise an alert at level 10 on a match.
Which version of Wazuh do I need?
Wazuh 4.x or later, with root access on the manager. Nothing else has to be installed: the integration uses the Python that ships with Wazuh.
Which indicators can I detect?
Malicious IP addresses and domains through the standard API, plus malicious URLs on Premium. In TAXII mode MD5, SHA-1 and SHA-256 hashes are added, matched against Sysmon events.
Can Wazuh block a malicious IP automatically?
Yes. Active Response is optional during installation. When it is on, Wazuh blocks a matching IP address on the local firewall for a period you set yourself.
Is there a free version?
Yes. The free Community edition lets you test the Wazuh integration before moving to Plus or Premium. The installer itself is open source under the Apache 2.0 licence.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access