Wazuh MCP Server: AI-Driven SOC Automation
-
Updated
Aug 26, 2026 - Python
Wazuh MCP Server: AI-Driven SOC Automation
In short, just give it access to your alerts.json, default rules, custom rules, archives.json, and magic happens.
Cloud Security & SOC portfolio with AWS labs, SIEM monitoring, and threat analysis. AWS | Wazuh | Splunk | Python
This project simulates real-world PowerShell-based fileless attacks and Living-off-the-Land (LotL) techniques against a Windows 11 endpoint, then detects them using Agent forwarded to a Wazuh SIEM.
Community-built Wazuh knowledge base — custom detection rules, SOC simulations, integrations, compliance labs, and Wazuh 5.0 migration guides. Open to all levels.
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
SOC analyst write-ups: malware analysis, YARA testing, threat detection
WaZuh XDR and SIEM Enhancements
Wazuh is a free, open-source security platform that unifies SIEM and XDR. It is designed to protect endpoints, such as servers, virtual machines, and cloud workloads, by monitoring them for threats.
Regras de correlação customizadas para Wazuh SIEM mapeadas ao MITRE ATT&CK
A custom SOC dashboard built on Wazuh for real-time security monitoring and incident investigation.
Web UI for tuning Wazuh 4.x `local_internal_options.conf` — generates ready-to-deploy config with matching OS-level hints (sysctl / limits.conf / systemd)
A Wazuh SIEM homelab built on a resource-constrained Proxmox host, with pfSense network segmentation and endpoint monitoring across Windows Server and Kali Linux hosts. Documenting the build, detection setup, and ongoing work.
mcp for Wazuh
Wazuh 4.9.1 modular deployment with Docker Compose and GitOps principles. Production-validated.
🛡️ Home SOC Lab — Full deployment documentation for a self-hosted SIEM using Wazuh, Sysmon, and open-source security tools. Includes FIM, vulnerability detection, MITRE ATT&CK mapping, and threat intelligence integration.
SOC Home Lab using Wazuh SIEM for detection and incident response
Enterprise-like home lab for hands-on cybersecurity and infrastructure practice.
Automated Security Lab Infrastructure. A DevSecOps portfolio project demonstrating modular IaC using OpenTofu/Terraform on Proxmox, featuring automated verification, SIEM deployment, and hardening pipelines.
Cybersecurity Portfolio featuring Defensive (SOC Analyst / Incident Response) & Offensive Security Projects.
Add a description, image, and links to the wazuh-siem topic page so that developers can more easily learn about it.
To associate your repository with the wazuh-siem topic, visit your repo's landing page and select "manage topics."