Sarker, ApurbaMondal, Joty ProkashSeraj, MehnazNoor, Jannatun2026-09-302026-09-302024-01-01A. Sarker, J. P. Mondal, M. Seraj and J. Noor, "Optimizing endpoint detection and monitoring in enterprise solution: A cyber threat intelligence approach," 2024 27th International Conference on Computer and Information Technology (ICCIT), Cox's Bazar, Bangladesh, 2024, pp. 2683-2688, doi: 10.1109/ICCIT64611.2024.11021895.97983315190942-s2.0-105009160235https://hdl.handle.net/10361/30301Advanced cyber threat intelligence systems are crucial at a time when enterprise solutions are increasing and are being targeted by more sophisticated cyberattacks. This research aims to improve endpoint detection and monitoring in enterprises by installing a Security Information and Event Management (SIEM) system based on Wazuh having an open-source robust and flexible Host Intrusion Detection System (HIDS) with integration into ELK Stack. The infrastructure creates a powerful combination of analytical security, intrusion detection, log data analysis, file integrity monitoring (FIM), and vulnerability management capabilities using the Wazuh active response module to detect security threats and continuous monitoring. Wazuh provides a robust and cost-effective solution that instantly detects and monitors simulated attacks such as denial-of-service (DoS) attacks by spotting suspicious file changes in real-time, SSH authentication failure, and identifying the root source of the flood of requests. This study also provides useful insights on designing and deploying comprehensive cybersecurity solutions with open-source tools such as Wazuh, making visual insights for file integrity monitoring (FIM) in real time.6 Pagesen-USVisualizationPrivacyScalabilityPipelinesNetwork intrusion detectionReal-time systemsThreat assessmentMalwareCyber threat intelligenceMonitoringWazuhSecurity Information and Event Management (SIEM)ELK StackEndpoint detectionReal-time monitoringDenial of Service (DoS) attackBrute-force attackFile Integrity Monitoring (FIM)Elastic-searchFilebeatComputer security.Optimizing endpoint detection and monitoring in enterprise solution: A cyber threat intelligence approachConference Proceeding10.1109/ICCIT64611.2024.11021895