AUTOMATION LIBRARY / 03

Three systems. One consistent investigation standard.

Open any project to inspect its architecture, capabilities, sample decision, and GitHub repository.

01

Wazuh + n8n

Wazuh SOC L1 Alert Triage

Normalizes Wazuh alerts, calculates risk, produces an analyst-ready report, and records every decision.

Tested live
02

Microsoft Sentinel + n8n

Microsoft Sentinel Incident Triage

Receives Sentinel incidents, builds entity context, scores risk, tracks analyst decisions, and reports daily performance.

Tested live
03

Wazuh + Splunk + Gemini + n8n

Wazuh + Splunk AI Log Analyzer

Analyzes uploaded SIEM logs, scores risk, maps MITRE ATT&CK, and produces an analyst-ready PDF report.

Tested locally