
Wazuh → n8n SOC Pipeline
A real-time alert pipeline that turns raw Wazuh detections into deduplicated, severity-routed notifications — built with n8n so triage doesn't start from a flooded inbox.
Detection pipelines, malware investigations, and adversary emulation. Each project includes the architecture, the evidence, and the lessons from getting it to work.

A real-time alert pipeline that turns raw Wazuh detections into deduplicated, severity-routed notifications — built with n8n so triage doesn't start from a flooded inbox.

Static and dynamic analysis of 5 real malware samples, fully isolated inside a REMnux sandbox — behavior, IOCs, and technique mapping documented for each one.

Five real malware investigations worked end-to-end from packet capture to Sigma rules and exported IOCs, mapped against MITRE ATT&CK the whole way.

A Splunk Cloud lab documenting Windows log ingestion and Sysmon forwarding, with detection searches for brute-force and PowerShell misuse written and tested end-to-end.
A lab-safe emulation range that replays real adversary playbooks so you can answer the only question that matters: would we actually have caught this?
A dual-chain pharmaceutical platform I built and then audited — 19 findings identified and remediated, including a reentrancy flaw, with security scanning wired into CI.
A local Gemma2 9B model triages real Wazuh detections and hands off to TheHive, Cortex, and MISP — 100% MITRE match vs. 40% for the SIEM baseline alone, with severity routing kept strictly off the LLM's own output.

A dual-mode hardening gateway that runs the same OWASP Top 10 exploits against a vulnerable and a hardened path of one app — plus a self-discovered drive-by localhost RCE and a stateful SIEM correlation engine.

A real Windows 10 endpoint monitored end-to-end: Sysmon telemetry into a Wazuh SIEM, validated with a genuinely causal 6-phase ATT&CK kill chain and 6 custom detection rules, every one verified firing against the live indexer.
Five NIST SP 800-61 / SANS-aligned runbooks — phishing, malware, account compromise, data breach, DDoS — each built as a decision tree, not a checklist, so any analyst on shift handles it the same way.
A RAG/agent system built twice — vulnerable and hardened — so every OWASP Top 10 for LLM fix can be demonstrated against the exact same attack, not described in the abstract.
Happy to walk through the architecture, the failed attempts, or the design decisions.