Sovereign kubernetes security operations center. Real-time false positives tuning
-
Updated
Aug 22, 2026 - Python
Sovereign kubernetes security operations center. Real-time false positives tuning
This repository hold a complete step by step documentation of the creation of a Security Operations Center SOC home lab.
A hands-on SOC Automation Lab built using Wazuh, TheHive, Cortex, and ELK. Demonstrates real-time threat detection, alert forwarding, and automated incident response in a simulated enterprise environment.
Agentic Physical Security Platform- Edge AI
An Open-source Ready SOC in a dockerized environment
A toolkit for SOC, NOC, Linux, Windows, IR, and ops work.
AI-powered SOC pipeline with triage, investigation, and response agents
Cybersecurity testing and research lab
This detection engineering repo is for the Detection as Code CI/CD pipeline
LogSourceCoverage is a lightweight monitoring layer built on top of Wazuh to provide visibility into the health and activity of security log sources.
Multi-module phishing website detection tool
A Security Operations Center (SOC) Home Lab showcasing endpoint telemetry collection, detection engineering, threat hunting and incident investigation using ELK Stack, Sysmon and Winlogbeat.
Sysmon-based detection engineering lab for MITRE T1059.001 (encoded PowerShell) and T1055 (abnormal parent-child process chains) on Windows 11.
Python script that reads mock security logs, detects suspicious patterns (e.g., brute force, failed logins, blacklisted IPs), and raises alerts.
robotic security operations with more than just dashboards. This goes into dispatching and more. Meant for event / city security ops with experimental robotics to assist. Code sanitized as much to still show a demo.
Cybersecurity lab demonstrating MITRE ATT&CK T1110 brute force attack simulation using Kali Linux and Hydra. Includes reconnaissance, attack execution, IoC analysis, and SOC defense strategies with Fail2Ban and 2FA implementation.
Week 2 SOC Internship – pfSense Firewall & pfBlockerNG Implementation
A modular SIEM Log Analysis & Threat Detection Engine in Python. Parses Linux Auth, Web (Apache/Nginx), and Syslogs to detect brute-force attacks, SQLi/XSS web payloads, privilege escalations, and directory scanners in real-time or batch mode, exporting interactive HTML dashboard reports and JSON audits.
Security log analysis engine - parses syslog, auth, Apache, and Windows event logs for threats
Live SDN monitoring dashboard — POX + Mininet + React.js
Add a description, image, and links to the securityoperationscenter topic page so that developers can more easily learn about it.
To associate your repository with the securityoperationscenter topic, visit your repo's landing page and select "manage topics."