<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>主机入侵检测 on XieJava's blog</title><link>http://xiejava.ishareread.com/tags/%E4%B8%BB%E6%9C%BA%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B/</link><description>Recent content in 主机入侵检测 on XieJava's blog</description><generator>Hugo</generator><language>zh-CN</language><copyright>XieJava</copyright><lastBuildDate>Thu, 08 Oct 2026 11:35:00 +0800</lastBuildDate><atom:link href="http://xiejava.ishareread.com/tags/%E4%B8%BB%E6%9C%BA%E5%85%A5%E4%BE%B5%E6%A3%80%E6%B5%8B/index.xml" rel="self" type="application/rss+xml"/><item><title>【一个人的SOC】(03) Wazuh 接入实战——把第一台主机纳管进你的 SOC</title><link>http://xiejava.ishareread.com/posts/f8d2a47c/</link><pubDate>Thu, 08 Oct 2026 11:35:00 +0800</pubDate><guid>http://xiejava.ishareread.com/posts/f8d2a47c/</guid><description>从一台裸机到 SOC 收到它的第一条告警：装 agent、跑通 wazuh-collector、Webhook 实时同步的取舍、踩过的 3 个真坑（API Key 不匹配/脚本权限错/${VAR} 密码解析）。本篇正式收编 7 篇旧 Wazuh 教程。</description></item></channel></rss>