01
Wazuh + n8n
Wazuh SOC L1 Alert Triage
Normalizes Wazuh alerts, calculates risk, produces an analyst-ready report, and records every decision.
Three production-shaped n8n systems for SOC triage and investigation across Wazuh, Splunk, and Microsoft Sentinel.
SELECTED WORK
Wazuh + n8n
Normalizes Wazuh alerts, calculates risk, produces an analyst-ready report, and records every decision.
Microsoft Sentinel + n8n
Receives Sentinel incidents, builds entity context, scores risk, tracks analyst decisions, and reports daily performance.
Wazuh + Splunk + Gemini + n8n
Analyzes uploaded SIEM logs, scores risk, maps MITRE ATT&CK, and produces an analyst-ready PDF report.
DESIGN PRINCIPLE
01Normalize before scoring
02Explain every risk decision
03Record analyst outcomes
04Measure false positives