Solutions/Wazuh AI SOC

Wazuh alert triage, handled by AI agents.

Keep Wazuh as your detection layer. AgentSOC takes its alerts as they fire, enriches and classifies each one, groups related alerts into incidents, and runs or recommends the response.

Keep your Wazuh deploymentForwarder on the Wazuh managerDetections tested under load
Start free
AgentSOC · SOC overview
AgentSOC dashboard
Keep Wazuh
No rip-and-replace. Wazuh stays your detection and log layer.
Real-time ingest
Wazuh alerts arrive in Jutsu as they fire.
Triaged and correlated
Severity, verdict, and threat-intel context, with alerts grouped into incidents.
Proven detections
Red Team and Firehose test that your Wazuh rules actually fire.
Explainer

Why Wazuh teams add an AI SOC.

Wazuh detects. Someone still has to triage.

Wazuh is an open-source security monitoring platform. It raises alerts from host monitoring, file-integrity checks, and threat-detection rules. Those alerts are only as useful as the triage behind them: someone has to decide which ones are real, which are related, and what to do about them.

On a small team, that someone can be the same engineer who runs the Wazuh manager. Jutsu adds the SOC layer on top of Wazuh: triage, enrichment, correlation, response, and reporting. Your detection setup stays as it is.

How the Wazuh connection works

A native forwarder runs on your Wazuh manager and posts alerts to the Jutsu Ingest API. From there, Wazuh alerts follow the same pipeline as every other source in AgentSOC.

  • Normalize: Wazuh alerts are mapped into the AgentSOC alert model.
  • Triage: each alert gets a category, severity, risk score, and verdict.
  • Enrich: indicators are checked against VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
  • Correlate: related alerts become incidents, including attack chains across hosts.
  • Respond: high-severity detections can trigger AgentSOAR playbooks or your own Shuffle workflows.

Prove your Wazuh detections work

Triage can only work on alerts Wazuh actually raises. Two other Jutsu products are built to test that. Red Team runs MITRE ATT&CK-mapped attack scenarios against authorized targets and scores which of your Wazuh detections fired. Firehose sends high-volume synthetic attack traffic to a Wazuh manager over TCP syslog and reports mean time to detect at p50, p95, and p99, so you know your pipeline holds up under load.

How it works

Three steps, end to end.

1

Install the forwarder

Run the Jutsu forwarder on your Wazuh manager to stream alerts to the Ingest API.

2

Agents triage each alert

Wazuh alerts are classified, enriched with threat intelligence, and correlated into incidents.

3

Respond or escalate

Confirmed threats run through response playbooks. Uncertain ones go to an analyst.

Capabilities

What Jutsu adds on top of Wazuh.

Real-time Wazuh ingest

Wazuh alerts arrive in Jutsu as they fire and become cases you can work.

AI triage verdicts

Category, severity, risk score, and verdict for every Wazuh alert.

Threat-intel enrichment

Indicators from Wazuh checked against reputation and threat feeds.

Incident correlation

Related Wazuh alerts grouped into incidents and multi-hop attack chains.

Response playbooks

High-severity detections can trigger AgentSOAR or Shuffle, with approvals.

Detection validation

Red Team and Firehose show what your Wazuh rules catch, and how fast.

FAQ

Common questions.

Give your Wazuh alerts a SOC.

Connect one Wazuh manager on the Free plan, or book a demo with our team.

Start free

Subscribe to our newsletter

Get the latest security tips, product updates, and news delivered to your inbox.