Skip to content
Best Practices

Wazuh SIEM, OpenBao Vault, and Coraza WAF: The Defensive Stack in SecTepe.Comm

|
|
6 min read

In 2026, defense in depth is no longer just a design tip. Auditors now require it. NIS-2 asks for layered defense in plain terms. ISO 27001:2022 requires continuous monitoring and secure configuration management. SecTepe.Comm bundles three open-source tools that give you exactly those layers: Wazuh, OpenBao and Coraza.

Wazuh: SIEM, EDR and Compliance Reports in One

Wazuh does more than collect logs. It brings together endpoint detection, log collection and compliance reports:

  • Endpoint agents run on Linux, Windows and macOS hosts. They check file integrity, find rootkits, scan for known flaws and assess the configuration.
  • Log collection pulls in syslog, Windows event logs, container logs (Docker, Kubernetes) and cloud APIs (AWS CloudTrail, Azure Activity Log).
  • Decoders and rules: More than 4,000 built-in rules cover common attack patterns. You can write your own rules in YAML.
  • MITRE ATT&CK mapping: Each alert links to the matching technique. This matters for incident response reports.
  • Compliance modules: Ready-made dashboards for PCI DSS, HIPAA, GDPR and NIST 800-53.

OpenBao: The Secrets Vault You Need

In 2026, secrets in plain-text config files will fail any serious audit. OpenBao is the free fork of HashiCorp Vault. It gives you:

  • One place for secrets: database passwords, API keys, TLS certificates and SSH CA keys.
  • Dynamic secrets: Database logins are created per session and expire soon after. They replace static passwords that last for years.
  • Transit engine: Encryption as a service for your apps. The app itself never holds the keys.
  • Audit trail: Each access to a secret is logged with the identity, the time and the method.
  • Link to your identity provider: OpenBao connects to Keycloak through OIDC. Access to secrets is tied to a real person, not to a service account.

Coraza: OWASP CRS in Traefik

In 2026, every app that is open to the internet needs a web application firewall. It is not your front line of defense. Its job is to filter out the 90 % of noise that comes from scanners and bots that try known exploits. Coraza implements the ModSecurity standard in pure Go and uses the OWASP Core Rule Set:

  • No Apache module to drag along: It runs as a sidecar or as a Traefik plugin. You do not need a separate WAF server.
  • Paranoia levels: From PL1 (default) to PL4 (very strict). You can set the level per app.
  • Custom rules: Write your own checks in SecRule syntax. Use allow-list rules to tune out false positives.
  • Audit log: Blocked requests, with the details of what matched, are passed on to Wazuh.

How the Three Work Together

Say an attacker tries an SQL injection on the SecTepe.Comm web UI. Here is what happens:

  1. Coraza spots the CRS pattern. It blocks the request with 403 and writes an audit entry.
  2. Wazuh reads the entry and links it to other activity from the same IP. Then it raises a high-severity alert.
  3. The alert starts a query on the OpenBao audit log. Did this IP or session access any secrets? If so, the tokens are revoked on the spot.
  4. The SOC gets a notice with the full context. No one has to dig through three tools by hand.

How Much Upkeep to Expect

Wazuh, OpenBao and Coraza are not a stack you install and forget. Here is a realistic view:

  • First setup: 2 to 3 days to configure, connect and tune the tools.
  • Ongoing work: 2 to 4 hours per week to sort out false positives, update rules and keep dashboards in shape.
  • Scale: The Wazuh Manager runs well on 8 vCPU and 16 GB RAM for about 500 endpoints. OpenBao and Coraza add almost no load.

Conclusion

Maybe you want real defense in depth in 2026, but you do not want to spend €50k a year on Splunk, HashiCorp Vault Enterprise and a WAF SaaS. Then Wazuh, OpenBao and Coraza give you a mature stack that fits together and keeps you EU-sovereign. The licenses are AGPL, MPL and Apache 2.0. The effort is easy to plan. The value in an audit is high.