Wazuh has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.
Wazuh is a free, open-source SIEM and XDR platform for log analysis,
intrusion detection, file-integrity monitoring, and vulnerability
detection across endpoints. Like Security Onion and Malcolm, it’s a
defensive/blue-team platform rather than an offensive toolkit, included
here for its official downloadable VM appliance.
Use it only in environments you own or are explicitly authorized to
monitor — see the disclaimer.
Getting started
Wazuh ships an official all-in-one OVA (built on Amazon Linux 2023)
that bundles the Wazuh indexer, server, and dashboard on a single
VM — import it into VirtualBox/VMware and it's ready with no separate
install step, though it doesn't provide high availability out of the
box. Endpoints run a lightweight Wazuh agent that ships logs,
file-integrity, and vulnerability data back to the server for
correlation. The official docs cover both this VM path and
distributed/cluster deployment for production use.
Before you continue
SecArsenal is an independent, educational reference. It does not host, distribute, or provide exploit code — only descriptions of, and links to, publicly available third-party tools and operating systems.
By continuing, you acknowledge that you will only use the tools and techniques referenced on this site against systems, networks, or accounts you own or are explicitly authorized to test; that unauthorized access to computer systems may be illegal in your jurisdiction; and that all information is provided "as is," and that SecArsenal and its contributors assume no liability for how it is used.
These change how this site looks and behaves in your browser only. Nothing is sent anywhere — your choices are saved on this device.
Larger text
Increases text size across the site by ~20%.
Extra spacing
Looser line, letter, and paragraph spacing in article text.
High contrast
Brighter muted text and borders, no decorative textures.
Always underline links
Identifies links by more than color alone.
Strong focus outline
A thicker, higher-contrast outline for keyboard navigation.
Reduce motion
Turns off hover/focus transitions, regardless of OS settings.
These toggles are a first-party enhancement layered on top of markup we build to follow WCAG 2.2 Level AA guidance — they are not a substitute for accessible design, and we have not undergone a formal third-party compliance audit, so we don't claim full conformance. If you hit a real accessibility barrier anywhere on this site, please open an issue — we'd rather hear about it than have this panel stand in for fixing it.