Wazuh Tutorial Shows How to Monitor Coraza WAF Events and Detect Web Attacks

· Original article ↗

Summary

The tutorial configures Caddy with Coraza and Wazuh to inspect web requests, collect WAF audit logs, detect common attacks and repeated activity, and monitor WAF configuration changes.

Key points

  • The demonstration places Coraza with the OWASP Core Rule Set in Caddy, inspecting HTTPS requests before they reach a DVWA web server.
  • Coraza audit logs are forwarded to Wazuh for centralized analysis; Wazuh also monitors /etc/caddy for configuration changes.
  • Custom rules detect SQL injection, cross-site scripting, path traversal or local file inclusion, and command injection attempts.
  • A correlation rule alerts on repeated attack detections from the same source within a short period.
  • The tutorial simulates attack requests and WAF configuration changes, then shows how to review resulting alerts in the Wazuh dashboard.

Article Details

Defense Focus
Block malicious web requests before they reach backend applications and centrally detect web attacks, repeated suspicious requests, and WAF configuration changes.
Detection Methods
  • Inspect decrypted HTTPS requests before reverse proxying them to the backend; evaluate OWASP CRS matches and interrupt transactions that reach the configured anomaly-score threshold.
  • Parse JSON WAF audit records and match attack-sqli, attack-xss, attack-lfi, and attack-rce tags in the messages field to detect SQL injection, cross-site scripting, path traversal or local file inclusion, and remote command execution attempts.
  • Include transaction.request.uri, transaction.client_ip, and transaction.is_interrupted in attack alerts to identify the requested resource, source address, and blocking outcome.
  • Correlate six web_attack alerts sharing transaction.client_ip within 60 seconds to flag repeated activity consistent with automated attack tooling.
  • Use real-time file integrity monitoring to detect file additions, modifications, and deletions under /etc/caddy.
  • Filter dashboard events with rule.groups:coraza and inspect decoded event fields to investigate generated alerts.
Data Sources
  • JSON WAF audit events from /var/log/coraza/audit.json, including transaction details and matched-rule messages.
  • File integrity monitoring events and reported content changes for /etc/caddy.
Rule Types
  • Custom XML detection rules using JSON decoding, parent-rule relationships, PCRE2 field matching, and alert groups.
  • Frequency and timeframe correlation rules keyed on transaction.client_ip.
  • File integrity monitoring rules matching configuration paths and file addition, modification, or deletion events.
  • SecLang configuration directives and OWASP CRS inspection rules.
  • Dashboard event-filter query using rule.groups:coraza.
Defensive Actions
  • Place WAF inspection before backend forwarding and enable blocking with SecRuleEngine On.
  • Enable relevant-transaction JSON audit logging and configure the endpoint agent to collect /var/log/coraza/audit.json.
  • Enable real-time monitoring with content-change reporting for /etc/caddy.
  • Restrict backend HTTP access to the WAF server and deny other connections to port 80.
  • Run the reverse proxy as a dedicated service account and restrict configuration-file permissions.
  • Rotate audit logs daily and retain a rolling 14-day history.
  • Install and reload the custom detection rules, then validate them with controlled injection, traversal, repeated-request, and configuration-change tests.
  • Review matching dashboard alerts and decoded transaction fields to investigate suspicious requests and configuration changes.

MITRE ATT&CK

Vendors

Products

Tools

Related Articles