main
md 1,759 lines 109 KB
Rendered Raw
1 # CoPilot Video Guide
2
3 This page is generated from the CoPilot YouTube playlist transcripts and is meant to be used like documentation.
4
5 ## Jump to your role
6
7 [I'm a SOC Operator](#operator-track)
8 [I'm an Admin/Engineer](#adminengineer-track)
9
10 ---
11
12 ## Browse by thumbnail
13
14 Use these thumbnail grids to jump straight to a video. Click the **thumbnail** to open YouTube in a new tab; click the **title** to jump to the summary on this page.
15
16 ### Operator thumbnails (SOC operators / analysts)
17
18 <div class="sf-thumb-grid" markdown>
19
20 <div class="sf-thumb-card" markdown>
21 <a href="https://www.youtube.com/watch?v=euFrHP0VkD8" target="_blank" rel="noopener">
22 <img src="https://img.youtube.com/vi/euFrHP0VkD8/hqdefault.jpg" alt="Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack" />
23 </a>
24 [Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack](#vid-euFrHP0VkD8)
25 <div class="sf-thumb-meta">Best for: Both</div>
26 </div>
27
28 <div class="sf-thumb-card" markdown>
29 <a href="https://www.youtube.com/watch?v=ffAnV31Ne54" target="_blank" rel="noopener">
30 <img src="https://img.youtube.com/vi/ffAnV31Ne54/hqdefault.jpg" alt="Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?" />
31 </a>
32 [Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?](#vid-ffAnV31Ne54)
33 <div class="sf-thumb-meta">Best for: Both</div>
34 </div>
35
36 <div class="sf-thumb-card" markdown>
37 <a href="https://www.youtube.com/watch?v=3p6qiH9UF8U" target="_blank" rel="noopener">
38 <img src="https://img.youtube.com/vi/3p6qiH9UF8U/hqdefault.jpg" alt="Powerful Wazuh Alert Management With CoPilot!" />
39 </a>
40 [Powerful Wazuh Alert Management With CoPilot!](#vid-3p6qiH9UF8U)
41 <div class="sf-thumb-meta">Best for: Operator</div>
42 </div>
43
44 <div class="sf-thumb-card" markdown>
45 <a href="https://www.youtube.com/watch?v=GwPyKM2X1EM" target="_blank" rel="noopener">
46 <img src="https://img.youtube.com/vi/GwPyKM2X1EM/hqdefault.jpg" alt="Introducing the Datastore in CoPilot: Upload Artifacts into Cases with Ease" />
47 </a>
48 [Introducing the Datastore in CoPilot: Upload Artifacts into Cases with Ease](#vid-GwPyKM2X1EM)
49 <div class="sf-thumb-meta">Best for: Operator</div>
50 </div>
51
52 <div class="sf-thumb-card" markdown>
53 <a href="https://www.youtube.com/watch?v=S2ELWusHcxA" target="_blank" rel="noopener">
54 <img src="https://img.youtube.com/vi/S2ELWusHcxA/hqdefault.jpg" alt="Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM" />
55 </a>
56 [Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM](#vid-S2ELWusHcxA)
57 <div class="sf-thumb-meta">Best for: Both</div>
58 </div>
59
60 <div class="sf-thumb-card" markdown>
61 <a href="https://www.youtube.com/watch?v=l9OLtgemYOQ" target="_blank" rel="noopener">
62 <img src="https://img.youtube.com/vi/l9OLtgemYOQ/hqdefault.jpg" alt="Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot" />
63 </a>
64 [Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot](#vid-l9OLtgemYOQ)
65 <div class="sf-thumb-meta">Best for: Both</div>
66 </div>
67
68 <div class="sf-thumb-card" markdown>
69 <a href="https://www.youtube.com/watch?v=R_pG1Gx_7O8" target="_blank" rel="noopener">
70 <img src="https://img.youtube.com/vi/R_pG1Gx_7O8/hqdefault.jpg" alt="Endpoint Investigation Made Easier: New Velociraptor Features in SOCFORTRESS CoPilot" />
71 </a>
72 [Endpoint Investigation Made Easier: New Velociraptor Features in SOCFORTRESS CoPilot](#vid-R_pG1Gx_7O8)
73 <div class="sf-thumb-meta">Best for: Operator</div>
74 </div>
75
76 <div class="sf-thumb-card" markdown>
77 <a href="https://www.youtube.com/watch?v=-2srPC-Dw-0" target="_blank" rel="noopener">
78 <img src="https://img.youtube.com/vi/-2srPC-Dw-0/hqdefault.jpg" alt="AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!" />
79 </a>
80 [AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!](#vid--2srPC-Dw-0)
81 <div class="sf-thumb-meta">Best for: Both</div>
82 </div>
83
84 <div class="sf-thumb-card" markdown>
85 <a href="https://www.youtube.com/watch?v=FHjD9QBaLD4" target="_blank" rel="noopener">
86 <img src="https://img.youtube.com/vi/FHjD9QBaLD4/hqdefault.jpg" alt="AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!" />
87 </a>
88 [AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!](#vid-FHjD9QBaLD4)
89 <div class="sf-thumb-meta">Best for: Both</div>
90 </div>
91
92 <div class="sf-thumb-card" markdown>
93 <a href="https://www.youtube.com/watch?v=QaLrmSgEcLI" target="_blank" rel="noopener">
94 <img src="https://img.youtube.com/vi/QaLrmSgEcLI/hqdefault.jpg" alt="AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!" />
95 </a>
96 [AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!](#vid-QaLrmSgEcLI)
97 <div class="sf-thumb-meta">Best for: Both</div>
98 </div>
99
100 <div class="sf-thumb-card" markdown>
101 <a href="https://www.youtube.com/watch?v=tguRiVgytso" target="_blank" rel="noopener">
102 <img src="https://img.youtube.com/vi/tguRiVgytso/hqdefault.jpg" alt="Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot" />
103 </a>
104 [Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot](#vid-tguRiVgytso)
105 <div class="sf-thumb-meta">Best for: Both</div>
106 </div>
107
108 <div class="sf-thumb-card" markdown>
109 <a href="https://www.youtube.com/watch?v=AH1g3p8s2_o" target="_blank" rel="noopener">
110 <img src="https://img.youtube.com/vi/AH1g3p8s2_o/hqdefault.jpg" alt="Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding" />
111 </a>
112 [Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding](#vid-AH1g3p8s2_o)
113 <div class="sf-thumb-meta">Best for: Both</div>
114 </div>
115
116 <div class="sf-thumb-card" markdown>
117 <a href="https://www.youtube.com/watch?v=llm3uSSUhqs" target="_blank" rel="noopener">
118 <img src="https://img.youtube.com/vi/llm3uSSUhqs/hqdefault.jpg" alt="Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!" />
119 </a>
120 [Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!](#vid-llm3uSSUhqs)
121 <div class="sf-thumb-meta">Best for: Both</div>
122 </div>
123
124 <div class="sf-thumb-card" markdown>
125 <a href="https://www.youtube.com/watch?v=Ko5jLfkSCrk" target="_blank" rel="noopener">
126 <img src="https://img.youtube.com/vi/Ko5jLfkSCrk/hqdefault.jpg" alt="Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle" />
127 </a>
128 [Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle](#vid-Ko5jLfkSCrk)
129 <div class="sf-thumb-meta">Best for: Both</div>
130 </div>
131
132 <div class="sf-thumb-card" markdown>
133 <a href="https://www.youtube.com/watch?v=GWTNA-6Z_Tk" target="_blank" rel="noopener">
134 <img src="https://img.youtube.com/vi/GWTNA-6Z_Tk/hqdefault.jpg" alt="Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts" />
135 </a>
136 [Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts](#vid-GWTNA-6Z_Tk)
137 <div class="sf-thumb-meta">Best for: Both</div>
138 </div>
139
140 <div class="sf-thumb-card" markdown>
141 <a href="https://www.youtube.com/watch?v=XT1d49HTqQw" target="_blank" rel="noopener">
142 <img src="https://img.youtube.com/vi/XT1d49HTqQw/hqdefault.jpg" alt="🚀 Master Sysmon Config Management with CoPilot & Wazuh!" />
143 </a>
144 [🚀 Master Sysmon Config Management with CoPilot & Wazuh!](#vid-XT1d49HTqQw)
145 <div class="sf-thumb-meta">Best for: Both</div>
146 </div>
147
148 <div class="sf-thumb-card" markdown>
149 <a href="https://www.youtube.com/watch?v=Ogr70DWAeTc" target="_blank" rel="noopener">
150 <img src="https://img.youtube.com/vi/Ogr70DWAeTc/hqdefault.jpg" alt="Supercharge Wazuh Active Response with CoPilot: No More Limits!" />
151 </a>
152 [Supercharge Wazuh Active Response with CoPilot: No More Limits!](#vid-Ogr70DWAeTc)
153 <div class="sf-thumb-meta">Best for: Both</div>
154 </div>
155
156 <div class="sf-thumb-card" markdown>
157 <a href="https://www.youtube.com/watch?v=TMJOBATTK9M" target="_blank" rel="noopener">
158 <img src="https://img.youtube.com/vi/TMJOBATTK9M/hqdefault.jpg" alt="Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot" />
159 </a>
160 [Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot](#vid-TMJOBATTK9M)
161 <div class="sf-thumb-meta">Best for: Both</div>
162 </div>
163
164 <div class="sf-thumb-card" markdown>
165 <a href="https://www.youtube.com/watch?v=tL3oNEx_3M8" target="_blank" rel="noopener">
166 <img src="https://img.youtube.com/vi/tL3oNEx_3M8/hqdefault.jpg" alt="Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team" />
167 </a>
168 [Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team](#vid-tL3oNEx_3M8)
169 <div class="sf-thumb-meta">Best for: Both</div>
170 </div>
171
172 <div class="sf-thumb-card" markdown>
173 <a href="https://www.youtube.com/watch?v=FJunzP2c_mQ" target="_blank" rel="noopener">
174 <img src="https://img.youtube.com/vi/FJunzP2c_mQ/hqdefault.jpg" alt="Auto-Enrich Wazuh Events with Threat Intel Feeds!" />
175 </a>
176 [Auto-Enrich Wazuh Events with Threat Intel Feeds!](#vid-FJunzP2c_mQ)
177 <div class="sf-thumb-meta">Best for: Both</div>
178 </div>
179
180 <div class="sf-thumb-card" markdown>
181 <a href="https://www.youtube.com/watch?v=CVVj9HRtjOE" target="_blank" rel="noopener">
182 <img src="https://img.youtube.com/vi/CVVj9HRtjOE/hqdefault.jpg" alt="Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data" />
183 </a>
184 [Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data](#vid-CVVj9HRtjOE)
185 <div class="sf-thumb-meta">Best for: Both</div>
186 </div>
187
188 <div class="sf-thumb-card" markdown>
189 <a href="https://www.youtube.com/watch?v=G3MDJSMvnRo" target="_blank" rel="noopener">
190 <img src="https://img.youtube.com/vi/G3MDJSMvnRo/hqdefault.jpg" alt="Simplify Cloud Security: ScoutSuite and Copilot Tutorial" />
191 </a>
192 [Simplify Cloud Security: ScoutSuite and Copilot Tutorial](#vid-G3MDJSMvnRo)
193 <div class="sf-thumb-meta">Best for: Both</div>
194 </div>
195
196 <div class="sf-thumb-card" markdown>
197 <a href="https://www.youtube.com/watch?v=Qnm9SXVJGWw" target="_blank" rel="noopener">
198 <img src="https://img.youtube.com/vi/Qnm9SXVJGWw/hqdefault.jpg" alt="Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!" />
199 </a>
200 [Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!](#vid-Qnm9SXVJGWw)
201 <div class="sf-thumb-meta">Best for: Both</div>
202 </div>
203
204 <div class="sf-thumb-card" markdown>
205 <a href="https://www.youtube.com/watch?v=-SVHKuQUxlI" target="_blank" rel="noopener">
206 <img src="https://img.youtube.com/vi/-SVHKuQUxlI/hqdefault.jpg" alt="Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning" />
207 </a>
208 [Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning](#vid--SVHKuQUxlI)
209 <div class="sf-thumb-meta">Best for: Both</div>
210 </div>
211
212 <div class="sf-thumb-card" markdown>
213 <a href="https://www.youtube.com/watch?v=fNybop2FTRE" target="_blank" rel="noopener">
214 <img src="https://img.youtube.com/vi/fNybop2FTRE/hqdefault.jpg" alt="Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment" />
215 </a>
216 [Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment](#vid-fNybop2FTRE)
217 <div class="sf-thumb-meta">Best for: Both</div>
218 </div>
219
220 <div class="sf-thumb-card" markdown>
221 <a href="https://www.youtube.com/watch?v=ixxVe_9LAfQ" target="_blank" rel="noopener">
222 <img src="https://img.youtube.com/vi/ixxVe_9LAfQ/hqdefault.jpg" alt="CoPilot + VirusTotal: Instantly Scan Files for Malware!" />
223 </a>
224 [CoPilot + VirusTotal: Instantly Scan Files for Malware!](#vid-ixxVe_9LAfQ)
225 <div class="sf-thumb-meta">Best for: Both</div>
226 </div>
227
228 <div class="sf-thumb-card" markdown>
229 <a href="https://www.youtube.com/watch?v=NUrnlTvLzVk" target="_blank" rel="noopener">
230 <img src="https://img.youtube.com/vi/NUrnlTvLzVk/hqdefault.jpg" alt="CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews" />
231 </a>
232 [CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews](#vid-NUrnlTvLzVk)
233 <div class="sf-thumb-meta">Best for: Both</div>
234 </div>
235
236 </div>
237
238 ### Admin/Engineer thumbnails (admins / engineers)
239
240 <div class="sf-thumb-grid" markdown>
241
242 <div class="sf-thumb-card" markdown>
243 <a href="https://www.youtube.com/watch?v=qQbex2zAhWI" target="_blank" rel="noopener">
244 <img src="https://img.youtube.com/vi/qQbex2zAhWI/hqdefault.jpg" alt="Copilot - Your Open Source Security Integrator" />
245 </a>
246 [Copilot - Your Open Source Security Integrator](#vid-qQbex2zAhWI)
247 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
248 </div>
249
250 <div class="sf-thumb-card" markdown>
251 <a href="https://www.youtube.com/watch?v=CQolYA30Gls" target="_blank" rel="noopener">
252 <img src="https://img.youtube.com/vi/CQolYA30Gls/hqdefault.jpg" alt="Copilot - Your Next Open Source Security Tool" />
253 </a>
254 [Copilot - Your Next Open Source Security Tool](#vid-CQolYA30Gls)
255 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
256 </div>
257
258 <div class="sf-thumb-card" markdown>
259 <a href="https://www.youtube.com/watch?v=seITDGXAiJw" target="_blank" rel="noopener">
260 <img src="https://img.youtube.com/vi/seITDGXAiJw/hqdefault.jpg" alt="CoPilot Install" />
261 </a>
262 [CoPilot Install](#vid-seITDGXAiJw)
263 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
264 </div>
265
266 <div class="sf-thumb-card" markdown>
267 <a href="https://www.youtube.com/watch?v=7dUHSMWWTuY" target="_blank" rel="noopener">
268 <img src="https://img.youtube.com/vi/7dUHSMWWTuY/hqdefault.jpg" alt="CoPilot Install -- Final Update (I Hope)" />
269 </a>
270 [CoPilot Install -- Final Update (I Hope)](#vid-7dUHSMWWTuY)
271 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
272 </div>
273
274 <div class="sf-thumb-card" markdown>
275 <a href="https://www.youtube.com/watch?v=euFrHP0VkD8" target="_blank" rel="noopener">
276 <img src="https://img.youtube.com/vi/euFrHP0VkD8/hqdefault.jpg" alt="Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack" />
277 </a>
278 [Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack](#vid-euFrHP0VkD8)
279 <div class="sf-thumb-meta">Best for: Both</div>
280 </div>
281
282 <div class="sf-thumb-card" markdown>
283 <a href="https://www.youtube.com/watch?v=ffAnV31Ne54" target="_blank" rel="noopener">
284 <img src="https://img.youtube.com/vi/ffAnV31Ne54/hqdefault.jpg" alt="Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?" />
285 </a>
286 [Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?](#vid-ffAnV31Ne54)
287 <div class="sf-thumb-meta">Best for: Both</div>
288 </div>
289
290 <div class="sf-thumb-card" markdown>
291 <a href="https://www.youtube.com/watch?v=S2ELWusHcxA" target="_blank" rel="noopener">
292 <img src="https://img.youtube.com/vi/S2ELWusHcxA/hqdefault.jpg" alt="Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM" />
293 </a>
294 [Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM](#vid-S2ELWusHcxA)
295 <div class="sf-thumb-meta">Best for: Both</div>
296 </div>
297
298 <div class="sf-thumb-card" markdown>
299 <a href="https://www.youtube.com/watch?v=31lCr80-NVM" target="_blank" rel="noopener">
300 <img src="https://img.youtube.com/vi/31lCr80-NVM/hqdefault.jpg" alt="Manage Wazuh Detection Rules with CoPilot" />
301 </a>
302 [Manage Wazuh Detection Rules with CoPilot](#vid-31lCr80-NVM)
303 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
304 </div>
305
306 <div class="sf-thumb-card" markdown>
307 <a href="https://www.youtube.com/watch?v=l9OLtgemYOQ" target="_blank" rel="noopener">
308 <img src="https://img.youtube.com/vi/l9OLtgemYOQ/hqdefault.jpg" alt="Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot" />
309 </a>
310 [Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot](#vid-l9OLtgemYOQ)
311 <div class="sf-thumb-meta">Best for: Both</div>
312 </div>
313
314 <div class="sf-thumb-card" markdown>
315 <a href="https://www.youtube.com/watch?v=-2srPC-Dw-0" target="_blank" rel="noopener">
316 <img src="https://img.youtube.com/vi/-2srPC-Dw-0/hqdefault.jpg" alt="AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!" />
317 </a>
318 [AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!](#vid--2srPC-Dw-0)
319 <div class="sf-thumb-meta">Best for: Both</div>
320 </div>
321
322 <div class="sf-thumb-card" markdown>
323 <a href="https://www.youtube.com/watch?v=FHjD9QBaLD4" target="_blank" rel="noopener">
324 <img src="https://img.youtube.com/vi/FHjD9QBaLD4/hqdefault.jpg" alt="AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!" />
325 </a>
326 [AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!](#vid-FHjD9QBaLD4)
327 <div class="sf-thumb-meta">Best for: Both</div>
328 </div>
329
330 <div class="sf-thumb-card" markdown>
331 <a href="https://www.youtube.com/watch?v=QaLrmSgEcLI" target="_blank" rel="noopener">
332 <img src="https://img.youtube.com/vi/QaLrmSgEcLI/hqdefault.jpg" alt="AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!" />
333 </a>
334 [AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!](#vid-QaLrmSgEcLI)
335 <div class="sf-thumb-meta">Best for: Both</div>
336 </div>
337
338 <div class="sf-thumb-card" markdown>
339 <a href="https://www.youtube.com/watch?v=tguRiVgytso" target="_blank" rel="noopener">
340 <img src="https://img.youtube.com/vi/tguRiVgytso/hqdefault.jpg" alt="Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot" />
341 </a>
342 [Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot](#vid-tguRiVgytso)
343 <div class="sf-thumb-meta">Best for: Both</div>
344 </div>
345
346 <div class="sf-thumb-card" markdown>
347 <a href="https://www.youtube.com/watch?v=AH1g3p8s2_o" target="_blank" rel="noopener">
348 <img src="https://img.youtube.com/vi/AH1g3p8s2_o/hqdefault.jpg" alt="Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding" />
349 </a>
350 [Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding](#vid-AH1g3p8s2_o)
351 <div class="sf-thumb-meta">Best for: Both</div>
352 </div>
353
354 <div class="sf-thumb-card" markdown>
355 <a href="https://www.youtube.com/watch?v=llm3uSSUhqs" target="_blank" rel="noopener">
356 <img src="https://img.youtube.com/vi/llm3uSSUhqs/hqdefault.jpg" alt="Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!" />
357 </a>
358 [Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!](#vid-llm3uSSUhqs)
359 <div class="sf-thumb-meta">Best for: Both</div>
360 </div>
361
362 <div class="sf-thumb-card" markdown>
363 <a href="https://www.youtube.com/watch?v=Ko5jLfkSCrk" target="_blank" rel="noopener">
364 <img src="https://img.youtube.com/vi/Ko5jLfkSCrk/hqdefault.jpg" alt="Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle" />
365 </a>
366 [Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle](#vid-Ko5jLfkSCrk)
367 <div class="sf-thumb-meta">Best for: Both</div>
368 </div>
369
370 <div class="sf-thumb-card" markdown>
371 <a href="https://www.youtube.com/watch?v=GWTNA-6Z_Tk" target="_blank" rel="noopener">
372 <img src="https://img.youtube.com/vi/GWTNA-6Z_Tk/hqdefault.jpg" alt="Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts" />
373 </a>
374 [Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts](#vid-GWTNA-6Z_Tk)
375 <div class="sf-thumb-meta">Best for: Both</div>
376 </div>
377
378 <div class="sf-thumb-card" markdown>
379 <a href="https://www.youtube.com/watch?v=XT1d49HTqQw" target="_blank" rel="noopener">
380 <img src="https://img.youtube.com/vi/XT1d49HTqQw/hqdefault.jpg" alt="🚀 Master Sysmon Config Management with CoPilot & Wazuh!" />
381 </a>
382 [🚀 Master Sysmon Config Management with CoPilot & Wazuh!](#vid-XT1d49HTqQw)
383 <div class="sf-thumb-meta">Best for: Both</div>
384 </div>
385
386 <div class="sf-thumb-card" markdown>
387 <a href="https://www.youtube.com/watch?v=Ogr70DWAeTc" target="_blank" rel="noopener">
388 <img src="https://img.youtube.com/vi/Ogr70DWAeTc/hqdefault.jpg" alt="Supercharge Wazuh Active Response with CoPilot: No More Limits!" />
389 </a>
390 [Supercharge Wazuh Active Response with CoPilot: No More Limits!](#vid-Ogr70DWAeTc)
391 <div class="sf-thumb-meta">Best for: Both</div>
392 </div>
393
394 <div class="sf-thumb-card" markdown>
395 <a href="https://www.youtube.com/watch?v=TMJOBATTK9M" target="_blank" rel="noopener">
396 <img src="https://img.youtube.com/vi/TMJOBATTK9M/hqdefault.jpg" alt="Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot" />
397 </a>
398 [Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot](#vid-TMJOBATTK9M)
399 <div class="sf-thumb-meta">Best for: Both</div>
400 </div>
401
402 <div class="sf-thumb-card" markdown>
403 <a href="https://www.youtube.com/watch?v=tL3oNEx_3M8" target="_blank" rel="noopener">
404 <img src="https://img.youtube.com/vi/tL3oNEx_3M8/hqdefault.jpg" alt="Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team" />
405 </a>
406 [Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team](#vid-tL3oNEx_3M8)
407 <div class="sf-thumb-meta">Best for: Both</div>
408 </div>
409
410 <div class="sf-thumb-card" markdown>
411 <a href="https://www.youtube.com/watch?v=MKqByrkDqZU" target="_blank" rel="noopener">
412 <img src="https://img.youtube.com/vi/MKqByrkDqZU/hqdefault.jpg" alt="Wazuh Indexer and CoPilot Integration" />
413 </a>
414 [Wazuh Indexer and CoPilot Integration](#vid-MKqByrkDqZU)
415 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
416 </div>
417
418 <div class="sf-thumb-card" markdown>
419 <a href="https://www.youtube.com/watch?v=MyvPmQ4Cfb0" target="_blank" rel="noopener">
420 <img src="https://img.youtube.com/vi/MyvPmQ4Cfb0/hqdefault.jpg" alt="Graylog and CoPilot Integration" />
421 </a>
422 [Graylog and CoPilot Integration](#vid-MyvPmQ4Cfb0)
423 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
424 </div>
425
426 <div class="sf-thumb-card" markdown>
427 <a href="https://www.youtube.com/watch?v=iI6yKgKC5wk" target="_blank" rel="noopener">
428 <img src="https://img.youtube.com/vi/iI6yKgKC5wk/hqdefault.jpg" alt="Wazuh Manager and CoPilot Integration" />
429 </a>
430 [Wazuh Manager and CoPilot Integration](#vid-iI6yKgKC5wk)
431 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
432 </div>
433
434 <div class="sf-thumb-card" markdown>
435 <a href="https://www.youtube.com/watch?v=-Cqyczg6ELE" target="_blank" rel="noopener">
436 <img src="https://img.youtube.com/vi/-Cqyczg6ELE/hqdefault.jpg" alt="Velociraptor and Copilot Integration" />
437 </a>
438 [Velociraptor and Copilot Integration](#vid--Cqyczg6ELE)
439 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
440 </div>
441
442 <div class="sf-thumb-card" markdown>
443 <a href="https://www.youtube.com/watch?v=vt6M1SzNfjE" target="_blank" rel="noopener">
444 <img src="https://img.youtube.com/vi/vt6M1SzNfjE/hqdefault.jpg" alt="CoPilot And InfluxDB - Monitor Your SIEM Stack Servers with InfluxDB and CoPilot!" />
445 </a>
446 [CoPilot And InfluxDB - Monitor Your SIEM Stack Servers with InfluxDB and CoPilot!](#vid-vt6M1SzNfjE)
447 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
448 </div>
449
450 <div class="sf-thumb-card" markdown>
451 <a href="https://www.youtube.com/watch?v=n9koQ1UL-L0" target="_blank" rel="noopener">
452 <img src="https://img.youtube.com/vi/n9koQ1UL-L0/hqdefault.jpg" alt="DFIR-IRIS and CoPilot - Bring your SOC Alerts into CoPilot" />
453 </a>
454 [DFIR-IRIS and CoPilot - Bring your SOC Alerts into CoPilot](#vid-n9koQ1UL-L0)
455 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
456 </div>
457
458 <div class="sf-thumb-card" markdown>
459 <a href="https://www.youtube.com/watch?v=FOOU1PQnd7g" target="_blank" rel="noopener">
460 <img src="https://img.youtube.com/vi/FOOU1PQnd7g/hqdefault.jpg" alt="Grafana and CoPilot Integration" />
461 </a>
462 [Grafana and CoPilot Integration](#vid-FOOU1PQnd7g)
463 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
464 </div>
465
466 <div class="sf-thumb-card" markdown>
467 <a href="https://www.youtube.com/watch?v=ihj2F2rA6BQ" target="_blank" rel="noopener">
468 <img src="https://img.youtube.com/vi/ihj2F2rA6BQ/hqdefault.jpg" alt="Seamless Office365 Integration with Wazuh: Simplified by Copilot" />
469 </a>
470 [Seamless Office365 Integration with Wazuh: Simplified by Copilot](#vid-ihj2F2rA6BQ)
471 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
472 </div>
473
474 <div class="sf-thumb-card" markdown>
475 <a href="https://www.youtube.com/watch?v=YOVUOpZDEzM" target="_blank" rel="noopener">
476 <img src="https://img.youtube.com/vi/YOVUOpZDEzM/hqdefault.jpg" alt="Unlock Full SIEM Potential: Effortlessly Ingest Crowdstrike Events Into Your Open Source SIEM!" />
477 </a>
478 [Unlock Full SIEM Potential: Effortlessly Ingest Crowdstrike Events Into Your Open Source SIEM!](#vid-YOVUOpZDEzM)
479 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
480 </div>
481
482 <div class="sf-thumb-card" markdown>
483 <a href="https://www.youtube.com/watch?v=tgWRvOJX5HA" target="_blank" rel="noopener">
484 <img src="https://img.youtube.com/vi/tgWRvOJX5HA/hqdefault.jpg" alt="CoPilot Event Shipper Configuration - Ingest 3rd Party Logs into your SIEM Stack" />
485 </a>
486 [CoPilot Event Shipper Configuration - Ingest 3rd Party Logs into your SIEM Stack](#vid-tgWRvOJX5HA)
487 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
488 </div>
489
490 <div class="sf-thumb-card" markdown>
491 <a href="https://www.youtube.com/watch?v=chTthkpMpTY" target="_blank" rel="noopener">
492 <img src="https://img.youtube.com/vi/chTthkpMpTY/hqdefault.jpg" alt="Unlock Full SIEM Potential: Effortlessly Ingest DUO MFA Events Into Your Open Source SIEM!" />
493 </a>
494 [Unlock Full SIEM Potential: Effortlessly Ingest DUO MFA Events Into Your Open Source SIEM!](#vid-chTthkpMpTY)
495 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
496 </div>
497
498 <div class="sf-thumb-card" markdown>
499 <a href="https://www.youtube.com/watch?v=wK4aA7QrXmE" target="_blank" rel="noopener">
500 <img src="https://img.youtube.com/vi/wK4aA7QrXmE/hqdefault.jpg" alt="New MITRE ATT&CK Integration in CoPilot – Game Changer for SOC Analysts!" />
501 </a>
502 [New MITRE ATT&CK Integration in CoPilot – Game Changer for SOC Analysts!](#vid-wK4aA7QrXmE)
503 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
504 </div>
505
506 <div class="sf-thumb-card" markdown>
507 <a href="https://www.youtube.com/watch?v=O5SaFwAMMtA" target="_blank" rel="noopener">
508 <img src="https://img.youtube.com/vi/O5SaFwAMMtA/hqdefault.jpg" alt="Supercharge Your Log Ingestion: Webhooks to SIEM Made Easy" />
509 </a>
510 [Supercharge Your Log Ingestion: Webhooks to SIEM Made Easy](#vid-O5SaFwAMMtA)
511 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
512 </div>
513
514 <div class="sf-thumb-card" markdown>
515 <a href="https://www.youtube.com/watch?v=FJunzP2c_mQ" target="_blank" rel="noopener">
516 <img src="https://img.youtube.com/vi/FJunzP2c_mQ/hqdefault.jpg" alt="Auto-Enrich Wazuh Events with Threat Intel Feeds!" />
517 </a>
518 [Auto-Enrich Wazuh Events with Threat Intel Feeds!](#vid-FJunzP2c_mQ)
519 <div class="sf-thumb-meta">Best for: Both</div>
520 </div>
521
522 <div class="sf-thumb-card" markdown>
523 <a href="https://www.youtube.com/watch?v=CVVj9HRtjOE" target="_blank" rel="noopener">
524 <img src="https://img.youtube.com/vi/CVVj9HRtjOE/hqdefault.jpg" alt="Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data" />
525 </a>
526 [Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data](#vid-CVVj9HRtjOE)
527 <div class="sf-thumb-meta">Best for: Both</div>
528 </div>
529
530 <div class="sf-thumb-card" markdown>
531 <a href="https://www.youtube.com/watch?v=G3MDJSMvnRo" target="_blank" rel="noopener">
532 <img src="https://img.youtube.com/vi/G3MDJSMvnRo/hqdefault.jpg" alt="Simplify Cloud Security: ScoutSuite and Copilot Tutorial" />
533 </a>
534 [Simplify Cloud Security: ScoutSuite and Copilot Tutorial](#vid-G3MDJSMvnRo)
535 <div class="sf-thumb-meta">Best for: Both</div>
536 </div>
537
538 <div class="sf-thumb-card" markdown>
539 <a href="https://www.youtube.com/watch?v=Qnm9SXVJGWw" target="_blank" rel="noopener">
540 <img src="https://img.youtube.com/vi/Qnm9SXVJGWw/hqdefault.jpg" alt="Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!" />
541 </a>
542 [Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!](#vid-Qnm9SXVJGWw)
543 <div class="sf-thumb-meta">Best for: Both</div>
544 </div>
545
546 <div class="sf-thumb-card" markdown>
547 <a href="https://www.youtube.com/watch?v=-SVHKuQUxlI" target="_blank" rel="noopener">
548 <img src="https://img.youtube.com/vi/-SVHKuQUxlI/hqdefault.jpg" alt="Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning" />
549 </a>
550 [Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning](#vid--SVHKuQUxlI)
551 <div class="sf-thumb-meta">Best for: Both</div>
552 </div>
553
554 <div class="sf-thumb-card" markdown>
555 <a href="https://www.youtube.com/watch?v=fNybop2FTRE" target="_blank" rel="noopener">
556 <img src="https://img.youtube.com/vi/fNybop2FTRE/hqdefault.jpg" alt="Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment" />
557 </a>
558 [Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment](#vid-fNybop2FTRE)
559 <div class="sf-thumb-meta">Best for: Both</div>
560 </div>
561
562 <div class="sf-thumb-card" markdown>
563 <a href="https://www.youtube.com/watch?v=ixxVe_9LAfQ" target="_blank" rel="noopener">
564 <img src="https://img.youtube.com/vi/ixxVe_9LAfQ/hqdefault.jpg" alt="CoPilot + VirusTotal: Instantly Scan Files for Malware!" />
565 </a>
566 [CoPilot + VirusTotal: Instantly Scan Files for Malware!](#vid-ixxVe_9LAfQ)
567 <div class="sf-thumb-meta">Best for: Both</div>
568 </div>
569
570 <div class="sf-thumb-card" markdown>
571 <a href="https://www.youtube.com/watch?v=NUrnlTvLzVk" target="_blank" rel="noopener">
572 <img src="https://img.youtube.com/vi/NUrnlTvLzVk/hqdefault.jpg" alt="CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews" />
573 </a>
574 [CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews](#vid-NUrnlTvLzVk)
575 <div class="sf-thumb-meta">Best for: Both</div>
576 </div>
577
578 <div class="sf-thumb-card" markdown>
579 <a href="https://www.youtube.com/watch?v=hC0JHY5WF-U" target="_blank" rel="noopener">
580 <img src="https://img.youtube.com/vi/hC0JHY5WF-U/hqdefault.jpg" alt="Wazuh Dashboards in Grafana & Customer Provisioning in CoPilot!" />
581 </a>
582 [Wazuh Dashboards in Grafana & Customer Provisioning in CoPilot!](#vid-hC0JHY5WF-U)
583 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
584 </div>
585
586 <div class="sf-thumb-card" markdown>
587 <a href="https://www.youtube.com/watch?v=9xHr5-Wlypw" target="_blank" rel="noopener">
588 <img src="https://img.youtube.com/vi/9xHr5-Wlypw/hqdefault.jpg" alt="Create Custom PDF Reports in Grafana Detailing Security Events | Share with Your Clients!" />
589 </a>
590 [Create Custom PDF Reports in Grafana Detailing Security Events | Share with Your Clients!](#vid-9xHr5-Wlypw)
591 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
592 </div>
593
594 <div class="sf-thumb-card" markdown>
595 <a href="https://www.youtube.com/watch?v=_bvFejcFwFM" target="_blank" rel="noopener">
596 <img src="https://img.youtube.com/vi/_bvFejcFwFM/hqdefault.jpg" alt="A Customer Portal for Your Open-Source SIEM Stack" />
597 </a>
598 [A Customer Portal for Your Open-Source SIEM Stack](#vid-_bvFejcFwFM)
599 <div class="sf-thumb-meta">Best for: Admin-Engineer</div>
600 </div>
601
602 </div>
603
604 ---
605 ## How to use this page
606
607 - Start with the section that matches your role.
608 - Videos labeled **Best for: Both** appear in *both* tracks below (by design).
609
610 <a id="operator-track"></a>
611
612 ## Operator Track (SOC operators / analysts)
613
614 Alert triage, case work, investigations, and day-to-day SOC workflows.
615
616 ### Core SOC Workflows: Alerting, Case Management, and Investigations
617
618 <a id="vid-euFrHP0VkD8"></a>
619 #### Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack
620 - Link: https://www.youtube.com/watch?v=euFrHP0VkD8
621 - Best for: Both
622 - What you learn:
623 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
624 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
625 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
626 - Shows connector setup steps and validation inside CoPilot.
627 - Highlights required service reload/restart points after configuration changes.
628 - Demonstrates alert flow from detection source into CoPilot incident views.
629 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
630 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
631 - Key CoPilot features shown: Wazuh integration, Graylog connector, Grafana integration, Incident management, Alert triage UI
632
633 <a id="vid-ffAnV31Ne54"></a>
634 #### Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?
635 - Link: https://www.youtube.com/watch?v=ffAnV31Ne54
636 - Best for: Both
637 - What you learn:
638 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
639 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
640 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
641 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
642 - Uses API-driven actions to push, pull, or validate security operations data.
643 - Shows practical filtering/search techniques for triage speed.
644 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
645 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
646 - Key CoPilot features shown: Wazuh integration, SCA visibility, Incident management, Alert triage UI
647
648 <a id="vid-3p6qiH9UF8U"></a>
649 #### Powerful Wazuh Alert Management With CoPilot!
650 - Link: https://www.youtube.com/watch?v=3p6qiH9UF8U
651 - Best for: Operator
652 - What you learn:
653 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
654 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
655 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
656 - Breaks down alert lifecycle handling and practical techniques for reducing analyst overload.
657 - Shows connector setup steps and validation inside CoPilot.
658 - Demonstrates alert flow from detection source into CoPilot incident views.
659 - Explains how index/search data is selected and mapped for operations.
660 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
661 - Key CoPilot features shown: Wazuh integration, Built-in case management, Incident management, Alert triage UI
662
663 <a id="vid-GwPyKM2X1EM"></a>
664 #### Introducing the Datastore in CoPilot: Upload Artifacts into Cases with Ease
665 - Link: https://www.youtube.com/watch?v=GwPyKM2X1EM
666 - Best for: Operator
667 - What you learn:
668 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
669 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
670 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
671 - Demonstrates uploading and attaching investigation artifacts directly into cases for evidence continuity.
672 - Walks through Docker Compose or service-level deployment changes.
673 - Demonstrates alert flow from detection source into CoPilot incident views.
674 - Demonstrates customer-aware workflows and tenant context handling.
675 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
676 - Key CoPilot features shown: Case datastore/artifact uploads, Incident management, Alert triage UI
677
678 <a id="vid-S2ELWusHcxA"></a>
679 #### Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM
680 - Link: https://www.youtube.com/watch?v=S2ELWusHcxA
681 - Best for: Both
682 - What you learn:
683 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
684 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
685 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
686 - Demonstrates alert flow from detection source into CoPilot incident views.
687 - Explains how index/search data is selected and mapped for operations.
688 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
689 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
690 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
691 - Key CoPilot features shown: Velociraptor integration, Sigma rule workflow, SCA visibility, Incident management, Alert triage UI
692
693 <a id="vid-l9OLtgemYOQ"></a>
694 #### Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot
695 - Link: https://www.youtube.com/watch?v=l9OLtgemYOQ
696 - Best for: Both
697 - What you learn:
698 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
699 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
700 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
701 - Explains how index/search data is selected and mapped for operations.
702 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
703 - Uses API-driven actions to push, pull, or validate security operations data.
704 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
705 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
706 - Key CoPilot features shown: Velociraptor integration, Active response automation, Vulnerability visibility, Incident management, Alert triage UI
707
708 <a id="vid-R_pG1Gx_7O8"></a>
709 #### Endpoint Investigation Made Easier: New Velociraptor Features in SOCFORTRESS CoPilot
710 - Link: https://www.youtube.com/watch?v=R_pG1Gx_7O8
711 - Best for: Operator
712 - What you learn:
713 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
714 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
715 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
716 - Demonstrates alert flow from detection source into CoPilot incident views.
717 - Uses API-driven actions to push, pull, or validate security operations data.
718 - Connects alert context to endpoint/asset details for analyst decision making.
719 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
720 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
721 - Key CoPilot features shown: Velociraptor integration, Incident management, Alert triage UI
722
723 ### AI Analyst and Assistant Workflows
724
725 <a id="vid--2srPC-Dw-0"></a>
726 #### AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!
727 - Link: https://www.youtube.com/watch?v=-2srPC-Dw-0
728 - Best for: Both
729 - What you learn:
730 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
731 - Shows how AI responses can accelerate common SOC questions and operational checks.
732 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
733 - Shows guided querying against CoPilot and backend systems using natural language prompts.
734 - Demonstrates alert flow from detection source into CoPilot incident views.
735 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
736 - Connects alert context to endpoint/asset details for analyst decision making.
737 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
738 - Key CoPilot features shown: Wazuh integration, AI analyst, AI-assisted investigation
739
740 <a id="vid-FHjD9QBaLD4"></a>
741 #### AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!
742 - Link: https://www.youtube.com/watch?v=FHjD9QBaLD4
743 - Best for: Both
744 - What you learn:
745 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
746 - Shows how AI responses can accelerate common SOC questions and operational checks.
747 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
748 - Shows guided querying against CoPilot and backend systems using natural language prompts.
749 - Walks through Docker Compose or service-level deployment changes.
750 - Demonstrates alert flow from detection source into CoPilot incident views.
751 - Explains how index/search data is selected and mapped for operations.
752 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
753 - Key CoPilot features shown: Wazuh integration, Velociraptor integration, AI agent, AI-assisted investigation
754
755 <a id="vid-QaLrmSgEcLI"></a>
756 #### AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!
757 - Link: https://www.youtube.com/watch?v=QaLrmSgEcLI
758 - Best for: Both
759 - What you learn:
760 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
761 - Shows how AI responses can accelerate common SOC questions and operational checks.
762 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
763 - Shows guided querying against CoPilot and backend systems using natural language prompts.
764 - Explains how index/search data is selected and mapped for operations.
765 - Uses API-driven actions to push, pull, or validate security operations data.
766 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
767 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
768 - Key CoPilot features shown: Velociraptor integration, AI chatbot, AI-assisted investigation
769
770 ### Detection Engineering and Response Automation
771
772 <a id="vid-tguRiVgytso"></a>
773 #### Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot
774 - Link: https://www.youtube.com/watch?v=tguRiVgytso
775 - Best for: Both
776 - What you learn:
777 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
778 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
779 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
780 - Shows connector setup steps and validation inside CoPilot.
781 - Walks through Docker Compose or service-level deployment changes.
782 - Demonstrates alert flow from detection source into CoPilot incident views.
783 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
784 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
785 - Key CoPilot features shown: Wazuh integration, Detection tuning
786
787 <a id="vid-AH1g3p8s2_o"></a>
788 #### Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding
789 - Link: https://www.youtube.com/watch?v=AH1g3p8s2_o
790 - Best for: Both
791 - What you learn:
792 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
793 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
794 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
795 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
796 - Walks through Docker Compose or service-level deployment changes.
797 - Highlights required service reload/restart points after configuration changes.
798 - Demonstrates alert flow from detection source into CoPilot incident views.
799 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
800 - Key CoPilot features shown: Wazuh integration, Detection tuning
801
802 <a id="vid-llm3uSSUhqs"></a>
803 #### Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!
804 - Link: https://www.youtube.com/watch?v=llm3uSSUhqs
805 - Best for: Both
806 - What you learn:
807 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
808 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
809 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
810 - Demonstrates response actions tied to detections, including safer execution and control boundaries.
811 - Highlights required service reload/restart points after configuration changes.
812 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
813 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
814 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
815 - Key CoPilot features shown: Wazuh integration, Active response automation, Detection tuning
816
817 <a id="vid-Ko5jLfkSCrk"></a>
818 #### Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle
819 - Link: https://www.youtube.com/watch?v=Ko5jLfkSCrk
820 - Best for: Both
821 - What you learn:
822 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
823 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
824 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
825 - Shows SOC automation orchestration by connecting CoPilot-driven alerts with Shuffle playbooks.
826 - Shows connector setup steps and validation inside CoPilot.
827 - Demonstrates alert flow from detection source into CoPilot incident views.
828 - Demonstrates customer-aware workflows and tenant context handling.
829 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
830 - Key CoPilot features shown: Shuffle SOAR integration, Detection tuning
831
832 <a id="vid-GWTNA-6Z_Tk"></a>
833 #### Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts
834 - Link: https://www.youtube.com/watch?v=GWTNA-6Z_Tk
835 - Best for: Both
836 - What you learn:
837 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
838 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
839 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
840 - Demonstrates alert flow from detection source into CoPilot incident views.
841 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
842 - Demonstrates customer-aware workflows and tenant context handling.
843 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
844 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
845 - Key CoPilot features shown: Velociraptor integration, Sigma rule workflow, Sysmon config management, Detection tuning
846
847 <a id="vid-XT1d49HTqQw"></a>
848 #### 🚀 Master Sysmon Config Management with CoPilot & Wazuh!
849 - Link: https://www.youtube.com/watch?v=XT1d49HTqQw
850 - Best for: Both
851 - What you learn:
852 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
853 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
854 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
855 - Shows connector setup steps and validation inside CoPilot.
856 - Highlights required service reload/restart points after configuration changes.
857 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
858 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
859 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
860 - Key CoPilot features shown: Wazuh integration, Sysmon config management, Detection tuning
861
862 <a id="vid-Ogr70DWAeTc"></a>
863 #### Supercharge Wazuh Active Response with CoPilot: No More Limits!
864 - Link: https://www.youtube.com/watch?v=Ogr70DWAeTc
865 - Best for: Both
866 - What you learn:
867 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
868 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
869 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
870 - Demonstrates response actions tied to detections, including safer execution and control boundaries.
871 - Highlights required service reload/restart points after configuration changes.
872 - Demonstrates alert flow from detection source into CoPilot incident views.
873 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
874 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
875 - Key CoPilot features shown: Wazuh integration, Active response automation, Detection tuning
876
877 <a id="vid-TMJOBATTK9M"></a>
878 #### Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot
879 - Link: https://www.youtube.com/watch?v=TMJOBATTK9M
880 - Best for: Both
881 - What you learn:
882 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
883 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
884 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
885 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
886 - Uses adversary simulation to validate that detection logic and alert routing behave as expected.
887 - Demonstrates alert flow from detection source into CoPilot incident views.
888 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
889 - Shows practical filtering/search techniques for triage speed.
890 - Key CoPilot features shown: Wazuh integration, Velociraptor integration, Atomic Red Team testing, Detection rule management, Detection tuning
891
892 <a id="vid-tL3oNEx_3M8"></a>
893 #### Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team
894 - Link: https://www.youtube.com/watch?v=tL3oNEx_3M8
895 - Best for: Both
896 - What you learn:
897 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
898 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
899 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
900 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
901 - Uses adversary simulation to validate that detection logic and alert routing behave as expected.
902 - Highlights required service reload/restart points after configuration changes.
903 - Demonstrates alert flow from detection source into CoPilot incident views.
904 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
905 - Key CoPilot features shown: Atomic Red Team testing, Detection rule management, Detection tuning
906
907 ### Threat Intelligence, Vulnerability, and Security Posture
908
909 <a id="vid-FJunzP2c_mQ"></a>
910 #### Auto-Enrich Wazuh Events with Threat Intel Feeds!
911 - Link: https://www.youtube.com/watch?v=FJunzP2c_mQ
912 - Best for: Both
913 - What you learn:
914 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
915 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
916 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
917 - Demonstrates alert flow from detection source into CoPilot incident views.
918 - Explains how index/search data is selected and mapped for operations.
919 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
920 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
921 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
922 - Key CoPilot features shown: Wazuh integration, Enrichment workflows
923
924 <a id="vid-CVVj9HRtjOE"></a>
925 #### Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data
926 - Link: https://www.youtube.com/watch?v=CVVj9HRtjOE
927 - Best for: Both
928 - What you learn:
929 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
930 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
931 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
932 - Demonstrates alert flow from detection source into CoPilot incident views.
933 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
934 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
935 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
936 - Key CoPilot features shown: Wazuh integration, Enrichment workflows
937
938 <a id="vid-G3MDJSMvnRo"></a>
939 #### Simplify Cloud Security: ScoutSuite and Copilot Tutorial
940 - Link: https://www.youtube.com/watch?v=G3MDJSMvnRo
941 - Best for: Both
942 - What you learn:
943 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
944 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
945 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
946 - Demonstrates customer-aware workflows and tenant context handling.
947 - Uses API-driven actions to push, pull, or validate security operations data.
948 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
949 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
950 - Key CoPilot features shown: SCA visibility, Enrichment workflows
951
952 <a id="vid-Qnm9SXVJGWw"></a>
953 #### Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!
954 - Link: https://www.youtube.com/watch?v=Qnm9SXVJGWw
955 - Best for: Both
956 - What you learn:
957 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
958 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
959 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
960 - Connects exposure data to prioritization so teams can address the highest-risk items first.
961 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
962 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
963 - Key CoPilot features shown: Wazuh integration, EPSS enrichment, Vulnerability visibility, Enrichment workflows
964
965 <a id="vid--SVHKuQUxlI"></a>
966 #### Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning
967 - Link: https://www.youtube.com/watch?v=-SVHKuQUxlI
968 - Best for: Both
969 - What you learn:
970 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
971 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
972 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
973 - Connects exposure data to prioritization so teams can address the highest-risk items first.
974 - Walks through Docker Compose or service-level deployment changes.
975 - Uses API-driven actions to push, pull, or validate security operations data.
976 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
977 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
978 - Key CoPilot features shown: DUO MFA ingestion, Nuclei scanning integration, SCA visibility, Vulnerability visibility, Enrichment workflows
979
980 <a id="vid-fNybop2FTRE"></a>
981 #### Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment
982 - Link: https://www.youtube.com/watch?v=fNybop2FTRE
983 - Best for: Both
984 - What you learn:
985 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
986 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
987 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
988 - Shows malware/IoC enrichment flow and how reputation context changes triage decisions.
989 - Shows connector setup steps and validation inside CoPilot.
990 - Walks through Docker Compose or service-level deployment changes.
991 - Demonstrates alert flow from detection source into CoPilot incident views.
992 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
993 - Key CoPilot features shown: Wazuh integration, VirusTotal enrichment, Enrichment workflows
994
995 <a id="vid-ixxVe_9LAfQ"></a>
996 #### CoPilot + VirusTotal: Instantly Scan Files for Malware!
997 - Link: https://www.youtube.com/watch?v=ixxVe_9LAfQ
998 - Best for: Both
999 - What you learn:
1000 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1001 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1002 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1003 - Shows malware/IoC enrichment flow and how reputation context changes triage decisions.
1004 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1005 - Shows connector setup steps and validation inside CoPilot.
1006 - Uses API-driven actions to push, pull, or validate security operations data.
1007 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1008 - Key CoPilot features shown: VirusTotal enrichment, SCA visibility, Enrichment workflows
1009
1010 <a id="vid-NUrnlTvLzVk"></a>
1011 #### CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews
1012 - Link: https://www.youtube.com/watch?v=NUrnlTvLzVk
1013 - Best for: Both
1014 - What you learn:
1015 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1016 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1017 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1018 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1019 - Explains how index/search data is selected and mapped for operations.
1020 - Demonstrates customer-aware workflows and tenant context handling.
1021 - Shows practical filtering/search techniques for triage speed.
1022 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1023 - Key CoPilot features shown: Wazuh integration, SCA visibility, Vulnerability visibility, Enrichment workflows
1024
1025 <a id="adminengineer-track"></a>
1026
1027 ## Admin/Engineer Track (admins / engineers)
1028
1029 Connecting sources, configuring integrations, tuning detections, reporting, and platform operations.
1030
1031 ### Start Here: Platform Overview and Installation
1032
1033 <a id="vid-qQbex2zAhWI"></a>
1034 #### Copilot - Your Open Source Security Integrator
1035 - Link: https://www.youtube.com/watch?v=qQbex2zAhWI
1036 - Best for: Admin-Engineer
1037 - What you learn:
1038 - Provides a guided orientation of CoPilot capabilities and where each module fits in day-to-day SOC operations.
1039 - Shows installation or upgrade flow with emphasis on prerequisites and expected post-install state.
1040 - Clarifies how CoPilot becomes the control plane across open-source SIEM and investigation tooling.
1041 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1042 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1043 - Provides a concise end-to-end example that connects configuration, validation, and operational usage.
1044 - Key CoPilot features shown: Platform onboarding
1045
1046 <a id="vid-CQolYA30Gls"></a>
1047 #### Copilot - Your Next Open Source Security Tool
1048 - Link: https://www.youtube.com/watch?v=CQolYA30Gls
1049 - Best for: Admin-Engineer
1050 - What you learn:
1051 - Provides a guided orientation of CoPilot capabilities and where each module fits in day-to-day SOC operations.
1052 - Shows installation or upgrade flow with emphasis on prerequisites and expected post-install state.
1053 - Clarifies how CoPilot becomes the control plane across open-source SIEM and investigation tooling.
1054 - Demonstrates alert flow from detection source into CoPilot incident views.
1055 - Demonstrates customer-aware workflows and tenant context handling.
1056 - Uses API-driven actions to push, pull, or validate security operations data.
1057 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1058 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1059 - Key CoPilot features shown: Grafana integration, Shuffle SOAR integration, Platform onboarding
1060
1061 <a id="vid-seITDGXAiJw"></a>
1062 #### CoPilot Install
1063 - Link: https://www.youtube.com/watch?v=seITDGXAiJw
1064 - Best for: Admin-Engineer
1065 - What you learn:
1066 - Provides a guided orientation of CoPilot capabilities and where each module fits in day-to-day SOC operations.
1067 - Shows installation or upgrade flow with emphasis on prerequisites and expected post-install state.
1068 - Clarifies how CoPilot becomes the control plane across open-source SIEM and investigation tooling.
1069 - Covers install/upgrade checkpoints and common misconfiguration pitfalls during initial setup.
1070 - Shows connector setup steps and validation inside CoPilot.
1071 - Walks through Docker Compose or service-level deployment changes.
1072 - Explains how index/search data is selected and mapped for operations.
1073 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1074 - Key CoPilot features shown: Platform onboarding
1075
1076 <a id="vid-7dUHSMWWTuY"></a>
1077 #### CoPilot Install -- Final Update (I Hope)
1078 - Link: https://www.youtube.com/watch?v=7dUHSMWWTuY
1079 - Best for: Admin-Engineer
1080 - What you learn:
1081 - Provides a guided orientation of CoPilot capabilities and where each module fits in day-to-day SOC operations.
1082 - Shows installation or upgrade flow with emphasis on prerequisites and expected post-install state.
1083 - Clarifies how CoPilot becomes the control plane across open-source SIEM and investigation tooling.
1084 - Covers install/upgrade checkpoints and common misconfiguration pitfalls during initial setup.
1085 - Shows connector setup steps and validation inside CoPilot.
1086 - Walks through Docker Compose or service-level deployment changes.
1087 - Highlights required service reload/restart points after configuration changes.
1088 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1089 - Key CoPilot features shown: Grafana integration, Platform onboarding
1090
1091 ### Core SOC Workflows: Alerting, Case Management, and Investigations
1092
1093 <a id="vid-euFrHP0VkD8"></a>
1094 #### Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack
1095 - Link: https://www.youtube.com/watch?v=euFrHP0VkD8
1096 - Best for: Both
1097 - What you learn:
1098 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
1099 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
1100 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
1101 - Shows connector setup steps and validation inside CoPilot.
1102 - Highlights required service reload/restart points after configuration changes.
1103 - Demonstrates alert flow from detection source into CoPilot incident views.
1104 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1105 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1106 - Key CoPilot features shown: Wazuh integration, Graylog connector, Grafana integration, Incident management, Alert triage UI
1107
1108 <a id="vid-ffAnV31Ne54"></a>
1109 #### Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?
1110 - Link: https://www.youtube.com/watch?v=ffAnV31Ne54
1111 - Best for: Both
1112 - What you learn:
1113 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
1114 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
1115 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
1116 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1117 - Uses API-driven actions to push, pull, or validate security operations data.
1118 - Shows practical filtering/search techniques for triage speed.
1119 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1120 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1121 - Key CoPilot features shown: Wazuh integration, SCA visibility, Incident management, Alert triage UI
1122
1123 <a id="vid-S2ELWusHcxA"></a>
1124 #### Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM
1125 - Link: https://www.youtube.com/watch?v=S2ELWusHcxA
1126 - Best for: Both
1127 - What you learn:
1128 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
1129 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
1130 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
1131 - Demonstrates alert flow from detection source into CoPilot incident views.
1132 - Explains how index/search data is selected and mapped for operations.
1133 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1134 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1135 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1136 - Key CoPilot features shown: Velociraptor integration, Sigma rule workflow, SCA visibility, Incident management, Alert triage UI
1137
1138 <a id="vid-31lCr80-NVM"></a>
1139 #### Manage Wazuh Detection Rules with CoPilot
1140 - Link: https://www.youtube.com/watch?v=31lCr80-NVM
1141 - Best for: Admin-Engineer
1142 - What you learn:
1143 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
1144 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
1145 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
1146 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
1147 - Highlights required service reload/restart points after configuration changes.
1148 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1149 - Uses API-driven actions to push, pull, or validate security operations data.
1150 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1151 - Key CoPilot features shown: Wazuh integration, Detection rule management, Incident management, Alert triage UI
1152
1153 <a id="vid-l9OLtgemYOQ"></a>
1154 #### Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot
1155 - Link: https://www.youtube.com/watch?v=l9OLtgemYOQ
1156 - Best for: Both
1157 - What you learn:
1158 - Walks through core alert-to-case workflow so analysts can move from detection to tracked investigation quickly.
1159 - Shows how context (customer, asset, enrichment data) is surfaced to reduce triage friction.
1160 - Demonstrates practical UI actions for prioritization, ownership, and investigation progress tracking.
1161 - Explains how index/search data is selected and mapped for operations.
1162 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1163 - Uses API-driven actions to push, pull, or validate security operations data.
1164 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1165 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1166 - Key CoPilot features shown: Velociraptor integration, Active response automation, Vulnerability visibility, Incident management, Alert triage UI
1167
1168 ### AI Analyst and Assistant Workflows
1169
1170 <a id="vid--2srPC-Dw-0"></a>
1171 #### AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!
1172 - Link: https://www.youtube.com/watch?v=-2srPC-Dw-0
1173 - Best for: Both
1174 - What you learn:
1175 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
1176 - Shows how AI responses can accelerate common SOC questions and operational checks.
1177 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
1178 - Shows guided querying against CoPilot and backend systems using natural language prompts.
1179 - Demonstrates alert flow from detection source into CoPilot incident views.
1180 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1181 - Connects alert context to endpoint/asset details for analyst decision making.
1182 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1183 - Key CoPilot features shown: Wazuh integration, AI analyst, AI-assisted investigation
1184
1185 <a id="vid-FHjD9QBaLD4"></a>
1186 #### AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!
1187 - Link: https://www.youtube.com/watch?v=FHjD9QBaLD4
1188 - Best for: Both
1189 - What you learn:
1190 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
1191 - Shows how AI responses can accelerate common SOC questions and operational checks.
1192 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
1193 - Shows guided querying against CoPilot and backend systems using natural language prompts.
1194 - Walks through Docker Compose or service-level deployment changes.
1195 - Demonstrates alert flow from detection source into CoPilot incident views.
1196 - Explains how index/search data is selected and mapped for operations.
1197 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1198 - Key CoPilot features shown: Wazuh integration, Velociraptor integration, AI agent, AI-assisted investigation
1199
1200 <a id="vid-QaLrmSgEcLI"></a>
1201 #### AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!
1202 - Link: https://www.youtube.com/watch?v=QaLrmSgEcLI
1203 - Best for: Both
1204 - What you learn:
1205 - Demonstrates natural-language investigation workflows that reduce manual querying in backend systems.
1206 - Shows how AI responses can accelerate common SOC questions and operational checks.
1207 - Covers the boundary between assisted analysis and operator validation for reliable decisions.
1208 - Shows guided querying against CoPilot and backend systems using natural language prompts.
1209 - Explains how index/search data is selected and mapped for operations.
1210 - Uses API-driven actions to push, pull, or validate security operations data.
1211 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1212 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1213 - Key CoPilot features shown: Velociraptor integration, AI chatbot, AI-assisted investigation
1214
1215 ### Detection Engineering and Response Automation
1216
1217 <a id="vid-tguRiVgytso"></a>
1218 #### Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot
1219 - Link: https://www.youtube.com/watch?v=tguRiVgytso
1220 - Best for: Both
1221 - What you learn:
1222 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1223 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1224 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1225 - Shows connector setup steps and validation inside CoPilot.
1226 - Walks through Docker Compose or service-level deployment changes.
1227 - Demonstrates alert flow from detection source into CoPilot incident views.
1228 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1229 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1230 - Key CoPilot features shown: Wazuh integration, Detection tuning
1231
1232 <a id="vid-AH1g3p8s2_o"></a>
1233 #### Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding
1234 - Link: https://www.youtube.com/watch?v=AH1g3p8s2_o
1235 - Best for: Both
1236 - What you learn:
1237 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1238 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1239 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1240 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
1241 - Walks through Docker Compose or service-level deployment changes.
1242 - Highlights required service reload/restart points after configuration changes.
1243 - Demonstrates alert flow from detection source into CoPilot incident views.
1244 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1245 - Key CoPilot features shown: Wazuh integration, Detection tuning
1246
1247 <a id="vid-llm3uSSUhqs"></a>
1248 #### Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!
1249 - Link: https://www.youtube.com/watch?v=llm3uSSUhqs
1250 - Best for: Both
1251 - What you learn:
1252 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1253 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1254 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1255 - Demonstrates response actions tied to detections, including safer execution and control boundaries.
1256 - Highlights required service reload/restart points after configuration changes.
1257 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1258 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1259 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1260 - Key CoPilot features shown: Wazuh integration, Active response automation, Detection tuning
1261
1262 <a id="vid-Ko5jLfkSCrk"></a>
1263 #### Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle
1264 - Link: https://www.youtube.com/watch?v=Ko5jLfkSCrk
1265 - Best for: Both
1266 - What you learn:
1267 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1268 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1269 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1270 - Shows SOC automation orchestration by connecting CoPilot-driven alerts with Shuffle playbooks.
1271 - Shows connector setup steps and validation inside CoPilot.
1272 - Demonstrates alert flow from detection source into CoPilot incident views.
1273 - Demonstrates customer-aware workflows and tenant context handling.
1274 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1275 - Key CoPilot features shown: Shuffle SOAR integration, Detection tuning
1276
1277 <a id="vid-GWTNA-6Z_Tk"></a>
1278 #### Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts
1279 - Link: https://www.youtube.com/watch?v=GWTNA-6Z_Tk
1280 - Best for: Both
1281 - What you learn:
1282 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1283 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1284 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1285 - Demonstrates alert flow from detection source into CoPilot incident views.
1286 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1287 - Demonstrates customer-aware workflows and tenant context handling.
1288 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1289 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1290 - Key CoPilot features shown: Velociraptor integration, Sigma rule workflow, Sysmon config management, Detection tuning
1291
1292 <a id="vid-XT1d49HTqQw"></a>
1293 #### 🚀 Master Sysmon Config Management with CoPilot & Wazuh!
1294 - Link: https://www.youtube.com/watch?v=XT1d49HTqQw
1295 - Best for: Both
1296 - What you learn:
1297 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1298 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1299 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1300 - Shows connector setup steps and validation inside CoPilot.
1301 - Highlights required service reload/restart points after configuration changes.
1302 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1303 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1304 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1305 - Key CoPilot features shown: Wazuh integration, Sysmon config management, Detection tuning
1306
1307 <a id="vid-Ogr70DWAeTc"></a>
1308 #### Supercharge Wazuh Active Response with CoPilot: No More Limits!
1309 - Link: https://www.youtube.com/watch?v=Ogr70DWAeTc
1310 - Best for: Both
1311 - What you learn:
1312 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1313 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1314 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1315 - Demonstrates response actions tied to detections, including safer execution and control boundaries.
1316 - Highlights required service reload/restart points after configuration changes.
1317 - Demonstrates alert flow from detection source into CoPilot incident views.
1318 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1319 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1320 - Key CoPilot features shown: Wazuh integration, Active response automation, Detection tuning
1321
1322 <a id="vid-TMJOBATTK9M"></a>
1323 #### Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot
1324 - Link: https://www.youtube.com/watch?v=TMJOBATTK9M
1325 - Best for: Both
1326 - What you learn:
1327 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1328 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1329 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1330 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
1331 - Uses adversary simulation to validate that detection logic and alert routing behave as expected.
1332 - Demonstrates alert flow from detection source into CoPilot incident views.
1333 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1334 - Shows practical filtering/search techniques for triage speed.
1335 - Key CoPilot features shown: Wazuh integration, Velociraptor integration, Atomic Red Team testing, Detection rule management, Detection tuning
1336
1337 <a id="vid-tL3oNEx_3M8"></a>
1338 #### Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team
1339 - Link: https://www.youtube.com/watch?v=tL3oNEx_3M8
1340 - Best for: Both
1341 - What you learn:
1342 - Shows how to move from static detections to repeatable engineering workflows for better signal quality.
1343 - Demonstrates automation patterns that reduce repetitive analyst actions during containment and response.
1344 - Covers testing/tuning loops so rule or response changes can be validated before broad rollout.
1345 - Shows rule editing/tuning workflow so detections can be refined without leaving CoPilot.
1346 - Uses adversary simulation to validate that detection logic and alert routing behave as expected.
1347 - Highlights required service reload/restart points after configuration changes.
1348 - Demonstrates alert flow from detection source into CoPilot incident views.
1349 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1350 - Key CoPilot features shown: Atomic Red Team testing, Detection rule management, Detection tuning
1351
1352 ### Integrations and Log Ingestion
1353
1354 <a id="vid-MKqByrkDqZU"></a>
1355 #### Wazuh Indexer and CoPilot Integration
1356 - Link: https://www.youtube.com/watch?v=MKqByrkDqZU
1357 - Best for: Admin-Engineer
1358 - What you learn:
1359 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1360 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1361 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1362 - Shows connector setup steps and validation inside CoPilot.
1363 - Explains how index/search data is selected and mapped for operations.
1364 - Uses API-driven actions to push, pull, or validate security operations data.
1365 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1366 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1367 - Key CoPilot features shown: Wazuh integration, Connector onboarding
1368
1369 <a id="vid-MyvPmQ4Cfb0"></a>
1370 #### Graylog and CoPilot Integration
1371 - Link: https://www.youtube.com/watch?v=MyvPmQ4Cfb0
1372 - Best for: Admin-Engineer
1373 - What you learn:
1374 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1375 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1376 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1377 - Shows connector setup steps and validation inside CoPilot.
1378 - Demonstrates alert flow from detection source into CoPilot incident views.
1379 - Explains how index/search data is selected and mapped for operations.
1380 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1381 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1382 - Key CoPilot features shown: Graylog connector, Connector onboarding
1383
1384 <a id="vid-iI6yKgKC5wk"></a>
1385 #### Wazuh Manager and CoPilot Integration
1386 - Link: https://www.youtube.com/watch?v=iI6yKgKC5wk
1387 - Best for: Admin-Engineer
1388 - What you learn:
1389 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1390 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1391 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1392 - Shows connector setup steps and validation inside CoPilot.
1393 - Uses API-driven actions to push, pull, or validate security operations data.
1394 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1395 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1396 - Key CoPilot features shown: Wazuh integration, Connector onboarding
1397
1398 <a id="vid--Cqyczg6ELE"></a>
1399 #### Velociraptor and Copilot Integration
1400 - Link: https://www.youtube.com/watch?v=-Cqyczg6ELE
1401 - Best for: Admin-Engineer
1402 - What you learn:
1403 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1404 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1405 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1406 - Shows connector setup steps and validation inside CoPilot.
1407 - Uses API-driven actions to push, pull, or validate security operations data.
1408 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1409 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1410 - Key CoPilot features shown: Velociraptor integration, Connector onboarding
1411
1412 <a id="vid-vt6M1SzNfjE"></a>
1413 #### CoPilot And InfluxDB - Monitor Your SIEM Stack Servers with InfluxDB and CoPilot!
1414 - Link: https://www.youtube.com/watch?v=vt6M1SzNfjE
1415 - Best for: Admin-Engineer
1416 - What you learn:
1417 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1418 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1419 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1420 - Shows connector setup steps and validation inside CoPilot.
1421 - Demonstrates alert flow from detection source into CoPilot incident views.
1422 - Uses API-driven actions to push, pull, or validate security operations data.
1423 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1424 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1425 - Key CoPilot features shown: Grafana integration, InfluxDB metrics integration, Connector onboarding
1426
1427 <a id="vid-n9koQ1UL-L0"></a>
1428 #### DFIR-IRIS and CoPilot - Bring your SOC Alerts into CoPilot
1429 - Link: https://www.youtube.com/watch?v=n9koQ1UL-L0
1430 - Best for: Admin-Engineer
1431 - What you learn:
1432 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1433 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1434 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1435 - Shows connector setup steps and validation inside CoPilot.
1436 - Demonstrates alert flow from detection source into CoPilot incident views.
1437 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1438 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1439 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1440 - Key CoPilot features shown: Built-in case management, SCA visibility, Connector onboarding
1441
1442 <a id="vid-FOOU1PQnd7g"></a>
1443 #### Grafana and CoPilot Integration
1444 - Link: https://www.youtube.com/watch?v=FOOU1PQnd7g
1445 - Best for: Admin-Engineer
1446 - What you learn:
1447 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1448 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1449 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1450 - Shows connector setup steps and validation inside CoPilot.
1451 - Demonstrates customer-aware workflows and tenant context handling.
1452 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1453 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1454 - Key CoPilot features shown: Grafana integration, Connector onboarding
1455
1456 <a id="vid-ihj2F2rA6BQ"></a>
1457 #### Seamless Office365 Integration with Wazuh: Simplified by Copilot
1458 - Link: https://www.youtube.com/watch?v=ihj2F2rA6BQ
1459 - Best for: Admin-Engineer
1460 - What you learn:
1461 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1462 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1463 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1464 - Explains how index/search data is selected and mapped for operations.
1465 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1466 - Demonstrates customer-aware workflows and tenant context handling.
1467 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1468 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1469 - Key CoPilot features shown: Wazuh integration, Office 365 connector, Connector onboarding
1470
1471 <a id="vid-YOVUOpZDEzM"></a>
1472 #### Unlock Full SIEM Potential: Effortlessly Ingest Crowdstrike Events Into Your Open Source SIEM!
1473 - Link: https://www.youtube.com/watch?v=YOVUOpZDEzM
1474 - Best for: Admin-Engineer
1475 - What you learn:
1476 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1477 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1478 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1479 - Demonstrates scalable ingestion patterns for third-party events into the security data pipeline.
1480 - Shows connector setup steps and validation inside CoPilot.
1481 - Walks through Docker Compose or service-level deployment changes.
1482 - Highlights required service reload/restart points after configuration changes.
1483 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1484 - Key CoPilot features shown: CrowdStrike ingestion, Customer portal, Connector onboarding
1485
1486 <a id="vid-tgWRvOJX5HA"></a>
1487 #### CoPilot Event Shipper Configuration - Ingest 3rd Party Logs into your SIEM Stack
1488 - Link: https://www.youtube.com/watch?v=tgWRvOJX5HA
1489 - Best for: Admin-Engineer
1490 - What you learn:
1491 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1492 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1493 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1494 - Demonstrates scalable ingestion patterns for third-party events into the security data pipeline.
1495 - Shows connector setup steps and validation inside CoPilot.
1496 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1497 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1498 - Key CoPilot features shown: DUO MFA ingestion, Event shipper, Connector onboarding
1499
1500 <a id="vid-chTthkpMpTY"></a>
1501 #### Unlock Full SIEM Potential: Effortlessly Ingest DUO MFA Events Into Your Open Source SIEM!
1502 - Link: https://www.youtube.com/watch?v=chTthkpMpTY
1503 - Best for: Admin-Engineer
1504 - What you learn:
1505 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1506 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1507 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1508 - Demonstrates scalable ingestion patterns for third-party events into the security data pipeline.
1509 - Walks through Docker Compose or service-level deployment changes.
1510 - Explains how index/search data is selected and mapped for operations.
1511 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1512 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1513 - Key CoPilot features shown: DUO MFA ingestion, Event shipper, Connector onboarding
1514
1515 <a id="vid-wK4aA7QrXmE"></a>
1516 #### New MITRE ATT&CK Integration in CoPilot – Game Changer for SOC Analysts!
1517 - Link: https://www.youtube.com/watch?v=wK4aA7QrXmE
1518 - Best for: Admin-Engineer
1519 - What you learn:
1520 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1521 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1522 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1523 - Explains ATT&CK mapping benefits for investigation context and coverage discussions.
1524 - Demonstrates alert flow from detection source into CoPilot incident views.
1525 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1526 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1527 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1528 - Key CoPilot features shown: MITRE ATT&CK mapping, Connector onboarding
1529
1530 <a id="vid-O5SaFwAMMtA"></a>
1531 #### Supercharge Your Log Ingestion: Webhooks to SIEM Made Easy
1532 - Link: https://www.youtube.com/watch?v=O5SaFwAMMtA
1533 - Best for: Admin-Engineer
1534 - What you learn:
1535 - Explains how to onboard external log sources and integrations into a consistent CoPilot workflow.
1536 - Shows field mapping and source-specific considerations so data arrives usable for alerting and triage.
1537 - Demonstrates validation steps to confirm events are flowing end-to-end into the SIEM/CoPilot pipeline.
1538 - Demonstrates scalable ingestion patterns for third-party events into the security data pipeline.
1539 - Shows connector setup steps and validation inside CoPilot.
1540 - Explains how index/search data is selected and mapped for operations.
1541 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1542 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1543 - Key CoPilot features shown: Webhook ingestion pipeline, Shuffle SOAR integration, Connector onboarding
1544
1545 ### Threat Intelligence, Vulnerability, and Security Posture
1546
1547 <a id="vid-FJunzP2c_mQ"></a>
1548 #### Auto-Enrich Wazuh Events with Threat Intel Feeds!
1549 - Link: https://www.youtube.com/watch?v=FJunzP2c_mQ
1550 - Best for: Both
1551 - What you learn:
1552 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1553 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1554 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1555 - Demonstrates alert flow from detection source into CoPilot incident views.
1556 - Explains how index/search data is selected and mapped for operations.
1557 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1558 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1559 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1560 - Key CoPilot features shown: Wazuh integration, Enrichment workflows
1561
1562 <a id="vid-CVVj9HRtjOE"></a>
1563 #### Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data
1564 - Link: https://www.youtube.com/watch?v=CVVj9HRtjOE
1565 - Best for: Both
1566 - What you learn:
1567 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1568 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1569 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1570 - Demonstrates alert flow from detection source into CoPilot incident views.
1571 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1572 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1573 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1574 - Key CoPilot features shown: Wazuh integration, Enrichment workflows
1575
1576 <a id="vid-G3MDJSMvnRo"></a>
1577 #### Simplify Cloud Security: ScoutSuite and Copilot Tutorial
1578 - Link: https://www.youtube.com/watch?v=G3MDJSMvnRo
1579 - Best for: Both
1580 - What you learn:
1581 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1582 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1583 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1584 - Demonstrates customer-aware workflows and tenant context handling.
1585 - Uses API-driven actions to push, pull, or validate security operations data.
1586 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1587 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1588 - Key CoPilot features shown: SCA visibility, Enrichment workflows
1589
1590 <a id="vid-Qnm9SXVJGWw"></a>
1591 #### Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!
1592 - Link: https://www.youtube.com/watch?v=Qnm9SXVJGWw
1593 - Best for: Both
1594 - What you learn:
1595 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1596 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1597 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1598 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1599 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1600 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1601 - Key CoPilot features shown: Wazuh integration, EPSS enrichment, Vulnerability visibility, Enrichment workflows
1602
1603 <a id="vid--SVHKuQUxlI"></a>
1604 #### Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning
1605 - Link: https://www.youtube.com/watch?v=-SVHKuQUxlI
1606 - Best for: Both
1607 - What you learn:
1608 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1609 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1610 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1611 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1612 - Walks through Docker Compose or service-level deployment changes.
1613 - Uses API-driven actions to push, pull, or validate security operations data.
1614 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1615 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1616 - Key CoPilot features shown: DUO MFA ingestion, Nuclei scanning integration, SCA visibility, Vulnerability visibility, Enrichment workflows
1617
1618 <a id="vid-fNybop2FTRE"></a>
1619 #### Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment
1620 - Link: https://www.youtube.com/watch?v=fNybop2FTRE
1621 - Best for: Both
1622 - What you learn:
1623 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1624 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1625 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1626 - Shows malware/IoC enrichment flow and how reputation context changes triage decisions.
1627 - Shows connector setup steps and validation inside CoPilot.
1628 - Walks through Docker Compose or service-level deployment changes.
1629 - Demonstrates alert flow from detection source into CoPilot incident views.
1630 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1631 - Key CoPilot features shown: Wazuh integration, VirusTotal enrichment, Enrichment workflows
1632
1633 <a id="vid-ixxVe_9LAfQ"></a>
1634 #### CoPilot + VirusTotal: Instantly Scan Files for Malware!
1635 - Link: https://www.youtube.com/watch?v=ixxVe_9LAfQ
1636 - Best for: Both
1637 - What you learn:
1638 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1639 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1640 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1641 - Shows malware/IoC enrichment flow and how reputation context changes triage decisions.
1642 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1643 - Shows connector setup steps and validation inside CoPilot.
1644 - Uses API-driven actions to push, pull, or validate security operations data.
1645 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1646 - Key CoPilot features shown: VirusTotal enrichment, SCA visibility, Enrichment workflows
1647
1648 <a id="vid-NUrnlTvLzVk"></a>
1649 #### CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews
1650 - Link: https://www.youtube.com/watch?v=NUrnlTvLzVk
1651 - Best for: Both
1652 - What you learn:
1653 - Shows how enrichment data is layered onto alerts to improve confidence and prioritization.
1654 - Demonstrates workflows for vulnerability, exposure, or threat context inside CoPilot operations.
1655 - Highlights how analysts can convert external intelligence into actionable triage or response steps.
1656 - Connects exposure data to prioritization so teams can address the highest-risk items first.
1657 - Explains how index/search data is selected and mapped for operations.
1658 - Demonstrates customer-aware workflows and tenant context handling.
1659 - Shows practical filtering/search techniques for triage speed.
1660 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1661 - Key CoPilot features shown: Wazuh integration, SCA visibility, Vulnerability visibility, Enrichment workflows
1662
1663 ### Operations, Reporting, and Customer Experience
1664
1665 <a id="vid-hC0JHY5WF-U"></a>
1666 #### Wazuh Dashboards in Grafana & Customer Provisioning in CoPilot!
1667 - Link: https://www.youtube.com/watch?v=hC0JHY5WF-U
1668 - Best for: Admin-Engineer
1669 - What you learn:
1670 - Focuses on operational maturity features for customer-facing SOC delivery and service consistency.
1671 - Shows how to package and present outcomes for stakeholders with less manual effort.
1672 - Demonstrates platform workflows that improve repeatability across customers and analysts.
1673 - Shows reporting/dashboard workflows to communicate security posture and outcomes clearly.
1674 - Demonstrates alert flow from detection source into CoPilot incident views.
1675 - Explains how index/search data is selected and mapped for operations.
1676 - Covers rule logic, filtering, or tuning considerations for higher-fidelity detections.
1677 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1678 - Key CoPilot features shown: Wazuh integration, Grafana integration, Multi-tenant operations
1679
1680 <a id="vid-9xHr5-Wlypw"></a>
1681 #### Create Custom PDF Reports in Grafana Detailing Security Events | Share with Your Clients!
1682 - Link: https://www.youtube.com/watch?v=9xHr5-Wlypw
1683 - Best for: Admin-Engineer
1684 - What you learn:
1685 - Focuses on operational maturity features for customer-facing SOC delivery and service consistency.
1686 - Shows how to package and present outcomes for stakeholders with less manual effort.
1687 - Demonstrates platform workflows that improve repeatability across customers and analysts.
1688 - Shows reporting/dashboard workflows to communicate security posture and outcomes clearly.
1689 - Shows connector setup steps and validation inside CoPilot.
1690 - Demonstrates alert flow from detection source into CoPilot incident views.
1691 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1692 - Emphasizes outcomes analysts/admins should verify after each configuration or workflow change.
1693 - Key CoPilot features shown: Grafana integration, Reporting workflow, Multi-tenant operations
1694
1695 <a id="vid-_bvFejcFwFM"></a>
1696 #### A Customer Portal for Your Open-Source SIEM Stack
1697 - Link: https://www.youtube.com/watch?v=_bvFejcFwFM
1698 - Best for: Admin-Engineer
1699 - What you learn:
1700 - Focuses on operational maturity features for customer-facing SOC delivery and service consistency.
1701 - Shows how to package and present outcomes for stakeholders with less manual effort.
1702 - Demonstrates platform workflows that improve repeatability across customers and analysts.
1703 - Introduces customer-facing portal workflows for transparent, self-service visibility.
1704 - Walks through Docker Compose or service-level deployment changes.
1705 - Demonstrates alert flow from detection source into CoPilot incident views.
1706 - Demonstrates customer-aware workflows and tenant context handling.
1707 - Includes practical walkthrough steps that can be replicated in production-like SOC environments.
1708 - Key CoPilot features shown: Customer portal, Multi-tenant operations
1709
1710 ## Index (all videos)
1711
1712 - [Copilot - Your Open Source Security Integrator](https://www.youtube.com/watch?v=qQbex2zAhWI)*Best for: Admin-Engineer*
1713 - [Copilot - Your Next Open Source Security Tool](https://www.youtube.com/watch?v=CQolYA30Gls)*Best for: Admin-Engineer*
1714 - [CoPilot Install](https://www.youtube.com/watch?v=seITDGXAiJw)*Best for: Admin-Engineer*
1715 - [CoPilot Install -- Final Update (I Hope)](https://www.youtube.com/watch?v=7dUHSMWWTuY)*Best for: Admin-Engineer*
1716 - [Wazuh Content Pack For Graylog - Easily Configure Your SOCFortress SIEM Stack](https://www.youtube.com/watch?v=euFrHP0VkD8)*Best for: Both*
1717 - [Wazuh Security Configuration Assessment and CoPilot - Are Your Endpoints Compliant?](https://www.youtube.com/watch?v=ffAnV31Ne54)*Best for: Both*
1718 - [Powerful Wazuh Alert Management With CoPilot!](https://www.youtube.com/watch?v=3p6qiH9UF8U)*Best for: Operator*
1719 - [Introducing the Datastore in CoPilot: Upload Artifacts into Cases with Ease](https://www.youtube.com/watch?v=GwPyKM2X1EM)*Best for: Operator*
1720 - [Supercharge Open-Source Cybersecurity: Velociraptor + Sigma for Your SIEM](https://www.youtube.com/watch?v=S2ELWusHcxA)*Best for: Both*
1721 - [Manage Wazuh Detection Rules with CoPilot](https://www.youtube.com/watch?v=31lCr80-NVM)*Best for: Admin-Engineer*
1722 - [Open Source SIEM Response | Dynamic Endpoint Actions with SOCFortress CoPilot](https://www.youtube.com/watch?v=l9OLtgemYOQ)*Best for: Both*
1723 - [Endpoint Investigation Made Easier: New Velociraptor Features in SOCFORTRESS CoPilot](https://www.youtube.com/watch?v=R_pG1Gx_7O8)*Best for: Operator*
1724 - [AI Analyst for Wazuh Alerts: Revolutionize Your SOC with SOCFortress Copilot!](https://www.youtube.com/watch?v=-2srPC-Dw-0)*Best for: Both*
1725 - [AI Agent for Open Source SIEM: Wazuh, Velociraptor + CoPilot!](https://www.youtube.com/watch?v=FHjD9QBaLD4)*Best for: Both*
1726 - [AI Chatbot Now With Threat Intel, Cyber News, Knowledge Base & Attack Surface!](https://www.youtube.com/watch?v=QaLrmSgEcLI)*Best for: Both*
1727 - [Automate Your SOC: Triggering Alerts with Wazuh Rules via Copilot](https://www.youtube.com/watch?v=tguRiVgytso)*Best for: Both*
1728 - [Wazuh Rule Writing With CoPilot AI Module - Handle Your Alert Flooding](https://www.youtube.com/watch?v=AH1g3p8s2_o)*Best for: Both*
1729 - [Mastering Wazuh's Active Response: Block Malicious IPs with CoPilot & Wazuh!](https://www.youtube.com/watch?v=llm3uSSUhqs)*Best for: Both*
1730 - [Revolutionize Your SIEM Alerts: Integrate CoPilot & Shuffle](https://www.youtube.com/watch?v=Ko5jLfkSCrk)*Best for: Both*
1731 - [Tame the Noise: Sigma Exclusions in CoPilot for Velociraptor Alerts](https://www.youtube.com/watch?v=GWTNA-6Z_Tk)*Best for: Both*
1732 - [🚀 Master Sysmon Config Management with CoPilot & Wazuh!](https://www.youtube.com/watch?v=XT1d49HTqQw)*Best for: Both*
1733 - [Supercharge Wazuh Active Response with CoPilot: No More Limits!](https://www.youtube.com/watch?v=Ogr70DWAeTc)*Best for: Both*
1734 - [Test Your Wazuh Detection Rules: One-Click Atomic Red Team + Velociraptor + CoPilot](https://www.youtube.com/watch?v=TMJOBATTK9M)*Best for: Both*
1735 - [Simulate Linux Attacks and Tune Detection Rules with Atomic Red Team](https://www.youtube.com/watch?v=tL3oNEx_3M8)*Best for: Both*
1736 - [Wazuh Indexer and CoPilot Integration](https://www.youtube.com/watch?v=MKqByrkDqZU)*Best for: Admin-Engineer*
1737 - [Graylog and CoPilot Integration](https://www.youtube.com/watch?v=MyvPmQ4Cfb0)*Best for: Admin-Engineer*
1738 - [Wazuh Manager and CoPilot Integration](https://www.youtube.com/watch?v=iI6yKgKC5wk)*Best for: Admin-Engineer*
1739 - [Velociraptor and Copilot Integration](https://www.youtube.com/watch?v=-Cqyczg6ELE)*Best for: Admin-Engineer*
1740 - [CoPilot And InfluxDB - Monitor Your SIEM Stack Servers with InfluxDB and CoPilot!](https://www.youtube.com/watch?v=vt6M1SzNfjE)*Best for: Admin-Engineer*
1741 - [DFIR-IRIS and CoPilot - Bring your SOC Alerts into CoPilot](https://www.youtube.com/watch?v=n9koQ1UL-L0)*Best for: Admin-Engineer*
1742 - [Grafana and CoPilot Integration](https://www.youtube.com/watch?v=FOOU1PQnd7g)*Best for: Admin-Engineer*
1743 - [Seamless Office365 Integration with Wazuh: Simplified by Copilot](https://www.youtube.com/watch?v=ihj2F2rA6BQ)*Best for: Admin-Engineer*
1744 - [Unlock Full SIEM Potential: Effortlessly Ingest Crowdstrike Events Into Your Open Source SIEM!](https://www.youtube.com/watch?v=YOVUOpZDEzM)*Best for: Admin-Engineer*
1745 - [CoPilot Event Shipper Configuration - Ingest 3rd Party Logs into your SIEM Stack](https://www.youtube.com/watch?v=tgWRvOJX5HA)*Best for: Admin-Engineer*
1746 - [Unlock Full SIEM Potential: Effortlessly Ingest DUO MFA Events Into Your Open Source SIEM!](https://www.youtube.com/watch?v=chTthkpMpTY)*Best for: Admin-Engineer*
1747 - [New MITRE ATT&CK Integration in CoPilot – Game Changer for SOC Analysts!](https://www.youtube.com/watch?v=wK4aA7QrXmE)*Best for: Admin-Engineer*
1748 - [Supercharge Your Log Ingestion: Webhooks to SIEM Made Easy](https://www.youtube.com/watch?v=O5SaFwAMMtA)*Best for: Admin-Engineer*
1749 - [Auto-Enrich Wazuh Events with Threat Intel Feeds!](https://www.youtube.com/watch?v=FJunzP2c_mQ)*Best for: Both*
1750 - [Analyzing Processes in Wazuh Alerts with Advanced Risk Scoring from Global Data](https://www.youtube.com/watch?v=CVVj9HRtjOE)*Best for: Both*
1751 - [Simplify Cloud Security: ScoutSuite and Copilot Tutorial](https://www.youtube.com/watch?v=G3MDJSMvnRo)*Best for: Both*
1752 - [Integrate EPSS with Wazuh for Top-Notch Vulnerability Management!](https://www.youtube.com/watch?v=Qnm9SXVJGWw)*Best for: Both*
1753 - [Enhancing Web App Security: Integrating Copilot with Nuclei for Vulnerability Scanning](https://www.youtube.com/watch?v=-SVHKuQUxlI)*Best for: Both*
1754 - [Boost CoPilot: IoCs from Wazuh + VirusTotal Enrichment](https://www.youtube.com/watch?v=fNybop2FTRE)*Best for: Both*
1755 - [CoPilot + VirusTotal: Instantly Scan Files for Malware!](https://www.youtube.com/watch?v=ixxVe_9LAfQ)*Best for: Both*
1756 - [CoPilot Supercharges Wazuh with SCA & Vulnerability Overviews](https://www.youtube.com/watch?v=NUrnlTvLzVk)*Best for: Both*
1757 - [Wazuh Dashboards in Grafana & Customer Provisioning in CoPilot!](https://www.youtube.com/watch?v=hC0JHY5WF-U)*Best for: Admin-Engineer*
1758 - [Create Custom PDF Reports in Grafana Detailing Security Events | Share with Your Clients!](https://www.youtube.com/watch?v=9xHr5-Wlypw)*Best for: Admin-Engineer*
1759 - [A Customer Portal for Your Open-Source SIEM Stack](https://www.youtube.com/watch?v=_bvFejcFwFM)*Best for: Admin-Engineer*