siem-logging
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the 'sigma-cli' package via pip and cloning official Docker configurations for Wazuh from GitHub. These are standard, well-known resources for security logging and detection engineering.
- [REMOTE_CODE_EXECUTION]: Instructions include downloading and deploying the Wazuh stack using Docker Compose. While this involves fetching and running external configurations, the source is a recognized security vendor and the process is standard for this type of software deployment.
- [COMMAND_EXECUTION]: The documentation provides multiple CLI command examples for AWS (securitylake), Azure (sentinel), and Kubernetes (kubectl) to facilitate the setup of logging infrastructure. These are instructional templates intended for the user's own cloud environment.
- [CREDENTIALS_UNSAFE]: Example templates for container orchestration (Docker and Kubernetes) contain hardcoded placeholder credentials such as 'SecurePassword123!'. These are clearly documented as templates for demonstration purposes with explicit instructions to update them for production use.
- [SAFE]: The skill references legitimate security research and official vendor documentation, including the MITRE ATT&CK framework and the Hacktricks security wiki, which are industry-standard references.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata