Wazuh detects. Someone still has to triage.
Wazuh is an open-source security monitoring platform. It raises alerts from host monitoring, file-integrity checks, and threat-detection rules. Those alerts are only as useful as the triage behind them: someone has to decide which ones are real, which are related, and what to do about them.
On a small team, that someone can be the same engineer who runs the Wazuh manager. Jutsu adds the SOC layer on top of Wazuh: triage, enrichment, correlation, response, and reporting. Your detection setup stays as it is.
How the Wazuh connection works
A native forwarder runs on your Wazuh manager and posts alerts to the Jutsu Ingest API. From there, Wazuh alerts follow the same pipeline as every other source in AgentSOC.
- Normalize: Wazuh alerts are mapped into the AgentSOC alert model.
- Triage: each alert gets a category, severity, risk score, and verdict.
- Enrich: indicators are checked against VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
- Correlate: related alerts become incidents, including attack chains across hosts.
- Respond: high-severity detections can trigger AgentSOAR playbooks or your own Shuffle workflows.
Prove your Wazuh detections work
Triage can only work on alerts Wazuh actually raises. Two other Jutsu products are built to test that. Red Team runs MITRE ATT&CK-mapped attack scenarios against authorized targets and scores which of your Wazuh detections fired. Firehose sends high-volume synthetic attack traffic to a Wazuh manager over TCP syslog and reports mean time to detect at p50, p95, and p99, so you know your pipeline holds up under load.
