Enterprise SIEM & Collaborative XDR Defense: Wazuh + CrowdSec

Architectural Summary

Unified threat visibility and active response across hybrid bare-metal nodes, Docker containers, and edge OpenWrt gateways. This architecture integrates Wazuh SIEM/XDR (endpoint detection, FIM, compliance mapping) with CrowdSec (behavioral log parsing, consensus threat intelligence, automated kernel firewall blocking).


◈ Detection & Response Pipeline

sequenceDiagram
    autonumber
    actor Attacker as Malicious IP
    participant Edge as OpenWrt Gateway (nftables)
    participant Host as Linux Node (Docker / Wazuh Agent)
    participant CS as CrowdSec Engine (Local API)
    participant WZ as Wazuh SIEM / OpenSearch Dashboard

    Attacker->>Edge: Port Scan / Exploitation Attempt
    Edge->>CS: Stream Ingress Syslog
    CS->>CS: Behavioral Rule Triggered (e.g. ssh-bf, http-crawl)
    CS->>Edge: Inject Immediate Netfilter Drop Rule (Bouncer)
    CS-->>WZ: Forward Alert Event via Syslog
    WZ->>WZ: Correlate with MITRE ATT&CK Framework
    WZ-->>Host: Trigger Active Response Script (Isolate Container / Revoke Token)

◈ Core Operational Capabilities

  1. Endpoint Integrity & File Integrity Monitoring (FIM):

    • Wazuh agents on all nodes monitor critical system directories (/etc, /usr/bin, /boot, /etc/uci-defaults) for unauthorized binary or configuration alterations.
  2. Collaborative Threat Intelligence (CrowdSec):

    • Parses logs across SSH traps, reverse proxies, and Honeypots.
    • Leverages global consensus blocklists to preemptively drop known malicious scanning networks at the border router before traffic reaches compute nodes.
  3. Regulatory Compliance Automation:

    • Automated compliance mapping against NIST 800-53, PCI-DSS 4.0, and CIS Benchmarks with weekly drift reports.