Wazuh SIEM
StoreFrame uses Wazuh as the platform-wide SIEM to monitor the security of every environment we manage.
StoreFrame runs Wazuh as the security monitoring layer across the entire fleet we manage — every customer Magento environment and the supporting infrastructure. A lightweight agent on each server continuously reports security-relevant signals to a central, StoreFrame-managed SIEM, giving our team continuous visibility into the security posture of the platform.
Wazuh complements the OS-level hardening and the application-layer security (CrowdSec, OpenResty + Lua security pipeline).
You don't interact with Wazuh directly as a customer — it runs as a background telemetry layer that StoreFrame uses to detect anomalies, audit compliance, and respond to threats across the fleet. Confirmed threats are acted on automatically, and the StoreFrame team is notified so it can respond.
What it monitors
- File integrity changes to sensitive system files and binaries
- System & audit events collected for centralized analysis
- CIS compliance continuous Security Configuration Assessment against the CIS Ubuntu benchmark (see CIS hardening)
- Vulnerability detection installed packages are checked against public CVE feeds
Related
- CIS hardening — OS-level controls the compliance module audits
- CrowdSec — application-layer threat detection
- OpenResty + Lua security pipeline — request-layer security signals