This is the practical workflow behind the Wazuh detection subset in HawkinsOperations, optimized for review speed and reproducibility.
Build a Wazuh rule set that maps to realistic SOC triage patterns, packages cleanly for deployment, and can be validated with a small set of commands from repo root.
detection-rules/wazuh/rules/.scripts/build-wazuh-bundle.ps1.<rule id= blocks separately.pwsh -File .\scripts\build-wazuh-bundle.ps1 (Get-ChildItem .\detection-rules\wazuh\rules -Filter *.xml).Count Select-String -Path .\detection-rules\wazuh\rules\*.xml ` -Pattern '
assets/screenshots/wazuh_bundle_build.pngassets/screenshots/wazuh_rule_fire_example.pngassets/screenshots/wazuh_count_validation.png