Wazuh SIEM Agent System
by flybfree
README.md
# Wazuh SIEM Agent System
A Claude-powered MCP tool suite for interacting with a Wazuh SIEM manager.
Exposes Wazuh REST API capabilities as MCP tools so Claude can triage alerts,
monitor agent health, hunt threats, manage rules, and propose/execute active responses.
## Architecture
```
wazuh-agent/
├── mcp/
│ └── wazuh_mcp_server.py # MCP server — all tools registered here
├── agents/
│ ├── orchestrator.py # Routes queries to the right specialist agent
│ ├── triage.py # Alert severity analysis & MITRE mapping
│ ├── health.py # Fleet connectivity & health checks
│ ├── hunting.py # IOC search & behavioural pattern detection
│ ├── rules.py # Rule analysis & coverage gaps
│ └── response.py # Active response proposals & gated execution
├── config.py # Connection settings (credentials via env vars)
└── requirements.txt
```
The MCP server imports analysis functions from each agent module and exposes them
as MCP tools. Claude (via Claude Code or another client) uses these tools to
reason over real-time Wazuh data.
## Setup
### 1. Install dependencies
```
pip install -r requirements.txt
```
### 2. Set credentials
Create a `.env` file (never commit this):
```
WAZUH_USER=your_api_user
WAZUH_PASSWORD=your_api_password
```
Or set environment variables directly in your shell.
### 3. Register the MCP server with Claude Code
Add to your Claude Code MCP settings (`claude_desktop_config.json` or `.claude/settings.json`):
```json
{
"mcpServers": {
"wazuh": {
"command": "python",
"args": ["G:/claudeai/wazuh-agent/mcp/wazuh_mcp_server.py"],
"env": {
"WAZUH_USER": "${WAZUH_USER}",
"WAZUH_PASSWORD": "${WAZUH_PASSWORD}"
}
}
}
}
```
## Available MCP Tools
### Raw API tools
| Tool | Description |
|------|-------------|
| `get_agents` | List all agents by status |
| `get_agent_details` | Details for a specific agent |
| `get_alerts` | Recent alerts with optional level/agent filter |
| `get_manager_info` | Manager version and status |
| `get_manager_stats` | Events/alerts per hour |
| `get_agent_processes` | Running processes (syscollector) |
| `get_agent_ports` | Open ports (syscollector) |
| `get_agent_packages` | Installed packages (syscollector) |
| `get_agent_vulnerabilities` | CVEs by agent and severity |
| `get_rules` | Search detection rules |
| `get_rule_by_id` | Look up a specific rule |
### Analysis tools
| Tool | Description |
|------|-------------|
| `triage_alerts` | Severity buckets, top rules, MITRE tactic counts |
| `check_health` | Fleet health: disconnected/stale agents, unknowns |
| `hunt_ioc` | Search all alerts for an IP, hash, domain, or username |
| `hunt_patterns` | Detect brute-force, lateral movement, priv-esc patterns |
| `analyze_rules` | Rule coverage summary and category breakdown |
| `propose_response` | Ranked active-response options (no execution) |
| `execute_active_response` | Execute a response — **requires `confirmed=True`** |
## Known Agents
| ID | Name | Notes |
|----|------|-------|
| 000 | wazuh | Manager |
| 001 | kali | |
| 002 | Area-51 | |
| 003 | Prism | |
| 004 | DESKTOP-GPLJ6GT | |
| 005 | vert-server | |
| 006 | pve610 | Disconnected |
| 007 | pve720XD | |
| 008 | pve720 | |
## Safety — Active Response
Active response commands modify target systems immediately and some are irreversible.
**The workflow is always:**
1. Call `propose_response(agent_id, threat_summary)` → review options
2. Present proposals to the user and get explicit approval
3. Call `execute_active_response(..., confirmed=True)` only after approval
`execute_active_response` called without `confirmed=True` returns a blocked status
and never touches the Wazuh API.
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues