About this project
This repository is a practical workshop for building a professional-grade Security Operations Center (SOC) system using Wazuh. It demonstrates a full incident response workflow: deploying a multi-node Wazuh SIEM (Indexer & Manager v4.7.5) via Docker Compose on an Ubuntu host, simulating a credential-stuffing attack with Kali Linux and Hydra, and then analyzing the resulting alerts and logs.
Key components include:
- **Architecture**: Ubuntu host as the endpoint, Wazuh SIEM in Docker, RAID 1 storage for logs, and Kali Linux as the attacker.
- **Skills**: SIEM engineering, endpoint hardening, digital forensics (DFIR), NIST CSF 2.0 alignment, incident response, threat mitigation (UFW firewall blocks), and technical communication.
- **Contents**: `/documentation` with incident reports (e.g., INC-2026-0709A), `/config` with hardened `ossec.conf` snippets, and `/artifacts` with forensic JSON logs.
- **Walkthroughs**: Three detailed documents covering detection, triage, and final reporting, all mapped to NIST frameworks.
All data has been sanitized for responsible disclosure. This is an excellent resource for learning SIEM operations, alert analysis, and structured incident response.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.