seim
Here are 28 public repositories matching this topic...
Hands-on SOC lab built with Wazuh, Sysmon, Suricata, VirusTotal, and Chainsaw to simulate, detect, and investigate RDP-based intrusions through SIEM monitoring, threat hunting, and incident analysis.
-
Updated
Jul 31, 2026
Notif360 is an open-source system monitoring and notification tool designed to provide comprehensive oversight of critical system metrics, website health, and malware scanning
-
Updated
Aug 28, 2025 - Shell
Enterprise-style Wazuh SIEM homelab featuring Windows & Linux monitoring, Sysmon, Auditd, custom detections, threat hunting, incident response, and MITRE ATT&CK mapping.
-
Updated
Jun 11, 2026
Sigma rules creation and deployment for threat detection using Wazuh SIEM. Includes Sigma YAML rules, automated Sigma-to-Wazuh XML conversion, MITRE ATT&CK mapping, and real-world PoC validation.
-
Updated
Sep 12, 2026 - Python
This repository stores tables for use in SEIM tools (specifically Sumologic)
-
Updated
Oct 16, 2020
Malware Analysis Lab using Wazuh & Sysmon for endpoint monitoring, threat hunting, MITRE ATT&CK mapping, and incident analysis.
-
Updated
Aug 20, 2026
Evidence-first, SIEM-agnostic AI security alert triage & investigation engine. Ingests alerts from multiple SIEM/EDR sources, deduplicates and correlates them into incidents, and produces explainable, evidence-backed AI analysis mapped to MITRE ATT&CK.
-
Updated
Sep 8, 2026 - Python
Splunk SIEM investigation lab with SPL detection rules, BOTS dataset analysis, and IR reports mapped to MITRE ATT&CK
-
Updated
Jun 14, 2026
Readable, RFC-compliant plain-text email alerts for Wazuh. A drop-in replacement for wazuh-maild that fixes truncated subjects, malformed headers, and messages rejected by strict MTAs for exceeding the 998-octet line limit. Single Python file, no dependencies, no external config.
-
Updated
Aug 13, 2026 - Python
Educational Wazuh SOC home lab for security monitoring, alert triage, log analysis, incident response and CTI enrichment.
-
Updated
Aug 18, 2026
Basic Intrusion Detection System using Scapy
-
Updated
Apr 4, 2026 - Python
Hands-on Wazuh SIEM deployment with Windows and Linux endpoints, File Integrity Monitoring (FIM), and Threat Hunting.
-
Updated
Jul 4, 2026
A self built log monitoring and alerting tool. Parses SSH auth logs with Bash and Python to detect brute force attacks and privilege escalation, renders the findings in a custom JavaScript dashboard, and ships with Splunk SPL queries for SIEM style correlation.
-
Updated
Jun 16, 2026 - HTML
My SOC Level 1 study notes from TryHackMe. Covers threat intelligence, SIEM investigations, digital forensics, endpoint monitoring, and phishing analysis, with practical labs using tools like Splunk, Wireshark, Sysmon, and Volatility.
-
Updated
May 30, 2026
CTI Lab 2 — Malicious File Analysis, ELK Stack, Purple Teaming (MITRE ATT&CK), and Elastic SIEM Alerting exercises. Tools: Sysmon, Atomic Red Team, Kibana, VirusTotal.
-
Updated
May 14, 2026
seim + idr without an api
-
Updated
Sep 29, 2025 - Python
Add this topic to your repo
To associate your repository with the seim topic, visit your repo's landing page and select "manage topics."