← Back to projects
CASE FILE 02 · SIEM / ENDPOINT SECURITY
Endpoint Security Monitoring & Vulnerability Assessment Using Wazuh
A centralized Wazuh SIEM environment deployed across Windows and Linux endpoints for log collection, FIM, SCA, security-event monitoring, alert analysis and vulnerability assessment.
Objective
Build a centralized monitoring environment that improves visibility across endpoints and supports vulnerability analysis and remediation prioritization.
Environment
- Centralized Wazuh SIEM setup.
- Windows and Linux endpoints.
- Security event and log collection.
- File Integrity Monitoring and Security Configuration Assessment.
Monitoring workflow
Collected endpoint logs and security events, reviewed alerts, analyzed host activity and used Wazuh capabilities to improve visibility into endpoint security conditions.
Vulnerability assessment
- Reviewed vulnerability findings and severity levels.
- Mapped affected endpoints and systems.
- Prioritized remediation requirements based on observed risk.
- Produced security reports and actionable remediation recommendations.
Outcome
The project demonstrated an end-to-end monitoring workflow from centralized visibility to vulnerability analysis and remediation reporting.