Skip to content
#

active-response

Here are 30 public repositories matching this topic...

Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. Connect Claude or any LLM to your SOC. OAuth 2.1, RBAC, multi-cluster, air-gap ready.

  • Updated Aug 21, 2026
  • Python

Enterprise Wazuh SIEM configuration with VirusTotal & MISP threat intelligence, OPNsense & MikroTik monitoring, automated active responses, Telegram SOC alerts, custom decoders/rules, and a Dockerized syslog collector. Includes MITRE ATT&CK mappings and ready-to-import dashboards.

  • Updated Apr 8, 2026
  • Python

This SOC semi-automation project integrates Wazuh, Shuffle, IRIS, MISP, Google Chat, and Grafana to handle and respond security incidents targeting DVWA on both Windows and Ubuntu. Goals: to execute automated security workflows for event collection, alert escalation, and incident response based on administrator decisions.

  • Updated Feb 9, 2026
  • Python

MODINE IDEAL: A High-Performance Cyber Defense & Intelligence Ecosystem. Engineered for proactive Threat Hunting, Zero-Day detection, and Automated Incident Response. Leveraging Wazuh and MITRE ATT&CK mapping to transform passive monitoring into an active security stronghold.

  • Updated Feb 26, 2026

Wazuh SOC home lab showcasing SIEM deployment, Windows and Linux endpoint monitoring, Sysmon, File Integrity Monitoring, custom alert tuning, and automated Active Response. Includes attack simulations, detection analysis, and Python-based SOAR-style enrichment.

  • Updated Jul 4, 2026
  • Python

Improve this page

Add a description, image, and links to the active-response topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the active-response topic, visit your repo's landing page and select "manage topics."

Learn more