SIEM / Detection Engineering
Wazuh Security Monitoring Lab
A home SIEM lab built around Wazuh — central manager, indexer and dashboard in Docker, agents on separate endpoints — then proven with controlled attacks rather than left as a running install.
- Wazuh manager, indexer and dashboard containerised on Docker, with agents enrolled from separate endpoints
- File integrity monitoring verified end-to-end, from activity on the endpoint through to the dashboard alert
- Simulated SSH brute-force with Hydra — the manager correlated repeated level 5 auth failures into level 8 and 10 alerts
- Docker container and network lifecycle events collected as security telemetry alongside OS events
- Traced an empty dashboard back to a credentials mismatch between Docker components, not the agent