Skip to content
#

active-response

Here are 23 public repositories matching this topic...

Enterprise Wazuh SIEM configuration with VirusTotal & MISP threat intelligence, OPNsense & MikroTik monitoring, automated active responses, Telegram SOC alerts, custom decoders/rules, and a Dockerized syslog collector. Includes MITRE ATT&CK mappings and ready-to-import dashboards.

  • Updated Apr 8, 2026
  • Python

This SOC semi-automation project integrates Wazuh, Shuffle, IRIS, MISP, Google Chat, and Grafana to handle and respond security incidents targeting DVWA on both Windows and Ubuntu. Goals: to execute automated security workflows for event collection, alert escalation, and incident response based on administrator decisions.

  • Updated Feb 9, 2026
  • Python

Wazuh SOC home lab showcasing SIEM deployment, Windows and Linux endpoint monitoring, Sysmon, File Integrity Monitoring, custom alert tuning, and automated Active Response. Includes attack simulations, detection analysis, and Python-based SOAR-style enrichment.

  • Updated Apr 7, 2026
  • Python

Improve this page

Add a description, image, and links to the active-response topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the active-response topic, visit your repo's landing page and select "manage topics."

Learn more