> For the complete documentation index, see [llms.txt](https://moharat.gitbook.io/cylabs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://moharat.gitbook.io/cylabs/security-domains/devsecops/wazuh-siem-and-xdr.md).

# Wazuh SIEM and XDR

Wazuh is Security Information and Event Management (SIEM) and Extended Detection and Response (XDR), which is capable of&#x20;

* Security monitoring
* IT assets protection using its capabilities
* File Integrity Monitoring (FIM)
* Security Configuration Assessment (SCA)
* Vulnerability Detection
* To enhance Organization's cybersecurity posture enhancement

**Use cases**&#x20;

* Configuration Management
* Malware Detection
* File Integrity Monitoring
* Threat Hunting
* Log Data Analysis
* Vulnerability Detection
* Incident Response
* Regulatory Compliance
* IT Hygiene
* Cloud Security
* Containers Security
* Posture Management
* Workload Protection

**Wazuh Components**

* Wazuh Indexer
* Wazuh Server
* Wazuh Dashboard
* Wazuh Endpoint

**Wazuh Architecture**

<figure><img src="/files/fVtlfITzDPqFQkOcWLjQ" alt=""><figcaption><p>Reference <a href="https://documentation.wazuh.com/current/getting-started/architecture.html">https://documentation.wazuh.com/current/getting-started/architecture.html</a></p></figcaption></figure>

**References:**&#x20;

{% embed url="<https://wazuh.com>" %}

{% embed url="<https://documentation.wazuh.com>" %}

{% embed url="<https://documentation.wazuh.com/current/getting-started/architecture.html>" %}

{% embed url="<https://github.com/wazuh>" %}
