
Wazuh
Open-source SIEM and XDR, running free inside Labshock.
Wazuh is an open-source security platform combining SIEM and XDR capabilities, covering log collection, rule-based detection, file integrity monitoring and alerting across hosts and services.
Inside Labshock it runs as a free lab — manager and dashboard deployed and already connected to a living industrial environment. No license, trial or card is required.
The reason it is free is the difference it demonstrates. A SIEM fed by static sample logs teaches the query language. A SIEM fed by a running industrial process teaches detection. Users trigger an action on the OT side, locate the matching event, write a rule, test whether it fires, then break something and read their own alert text.
OT events reach Wazuh through Tidal Collector, which normalises SCADA actions, PLC state changes and process signals into the ingestion pipeline.
Detection is where OT security stops being theoretical, and it is the hardest thing to practise.
Production is not a place to test rules, and a pile of sample logs does not behave like a plant. So detection becomes the skill people read about and never exercise — backwards, in a discipline where a missed alert has physical consequences.
Wazuh is free inside Labshock because the license was never the obstacle. Access to a process you are allowed to test was.
