Security automation that makes every alert explainable.

Three production-shaped n8n systems for SOC triage and investigation across Wazuh, Splunk, and Microsoft Sentinel.

03 AUTOMATIONS07 TESTED WORKFLOWS02 SIEM FORMATSEND-TO-END TESTED

SELECTED WORK

Built for the first decisions that shape an incident.

01

Wazuh + n8n

Wazuh SOC L1 Alert Triage

Normalizes Wazuh alerts, calculates risk, produces an analyst-ready report, and records every decision.

Tested live
02

Microsoft Sentinel + n8n

Microsoft Sentinel Incident Triage

Receives Sentinel incidents, builds entity context, scores risk, tracks analyst decisions, and reports daily performance.

Tested live
03

Wazuh + Splunk + Gemini + n8n

Wazuh + Splunk AI Log Analyzer

Analyzes uploaded SIEM logs, scores risk, maps MITRE ATT&CK, and produces an analyst-ready PDF report.

Tested locally

DESIGN PRINCIPLE

Automation assists the analyst. It does not hide the evidence.

01Normalize before scoring

02Explain every risk decision

03Record analyst outcomes

04Measure false positives