wazuh / wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
https://wazuh.com/
Other
9.34k stars 1.48k forks source link

Integration of MaxMind GeoIP and ASN Databases into Wazuh-Engine #23337

Closed juliancnn closed 1 week ago

juliancnn commented 1 week ago
Related issue
#21695

Description

This PR represents a comprehensive effort to integrate MaxMind's GeoIP and ASN databases into the Wazuh-Engine, as outlined in the epic https://github.com/wazuh/wazuh/issues/21695. The integration aims to enhance the engine's data analysis and threat intelligence capabilities by enriching events with geographical and autonomous system number (ASN) information.

Objectives

Key Achievements

Changes Included in This PR

Additional Considerations

Acceptance Criteria

This PR is a significant step forward in advancing the capabilities of the Wazuh-Engine, providing enhanced contextual data that supports more sophisticated analysis and threat detection strategies.