Skip to content

Services · Wazuh · SIEM · SOC automation

Security engineering that makes your SOC actually work.

Pick a service, fill a short form, and it reaches me directly on WhatsApp or email. Scope and terms are agreed before any work begins.

01

Primary specialization

Wazuh SIEM architecture & detection engineering

  • Wazuh
  • Wazuh FIM/SCA
  • OpenSearch
  • Ansible
  • AWS EC2
  • Linux
  • Windows

Client situation

You need a reliable Wazuh foundation: deployed correctly, tuned for your environment, and producing alerts you can trust.

Proposed scope

Wazuh Manager, Indexer, Dashboard and agent deployment (Linux, Windows, AWS), FIM, SCA, vulnerability detection, custom XML decoders and rules, and tenant separation where needed.

Deliverables

  • Architecture & configuration summary
  • Custom decoders and rules
  • Agent onboarding checklist
  • Validation results and operating notes

Relevant evidence

02

ELK & OpenSearch stack engineering

  • Elasticsearch
  • Logstash
  • Kibana
  • OpenSearch
  • Wazuh
  • Kafka

Client situation

Your Elasticsearch cluster is slow, mappings are messy, or logs are not flowing the way your team needs.

Proposed scope

Elasticsearch, Logstash and Kibana (or OpenSearch) deployment and tuning: index lifecycle management, mapping and template design, ingestion pipelines, dashboards, and Wazuh integration.

Deliverables

  • Stack architecture & sizing notes
  • Ingestion pipelines and mappings
  • Kibana/OpenSearch dashboards
  • Retention and tuning guidance

Relevant evidence

03

Enterprise SIEM & multi-platform log engineering

  • Splunk
  • IBM QRadar
  • Microsoft Sentinel
  • ELK/Elastic
  • OpenSearch
  • Grafana

Client situation

Important logs are missing, alerts lack context, or detections across your SIEM need review and tuning.

Proposed scope

Log ingestion and parsing for selected sources, field validation, event correlation, detection rule tuning, false-positive reduction, and dashboard views.

Deliverables

  • Integration notes
  • Detection logic and tuning changes
  • Test cases and observed results
  • Prioritized recommendations

Relevant evidence

04

SOC workflow automation & SOAR pipelines

  • n8n
  • Shuffle
  • Python
  • Webhooks
  • Slack
  • Jira
  • MCP

Client situation

Analysts repeatedly copy alert details into tickets or notify teams manually.

Proposed scope

Design and implement agreed alert routing, severity-based escalation, automatic ticket/case creation, and team notifications.

Time savings are only discussed after measuring your current baseline.

Deliverables

  • Workflow diagram
  • Configured automation
  • Validation notes
  • Maintenance guidance

Relevant evidence

05

Endpoint telemetry & behavioral detection

  • Sysmon
  • Auditd
  • CrowdStrike
  • Suricata
  • YARA
  • MITRE ATT&CK

Client situation

You lack visibility into what actually happens on endpoints and the network: process abuse, LOLBins, suspicious files.

Proposed scope

Sysmon and Auditd telemetry design, behavioral detections mapped to MITRE ATT&CK, YARA file scanning, and network inspection with Suricata.

Deliverables

  • Telemetry configuration
  • Behavioral detection rules
  • MITRE ATT&CK mapping
  • Test results

Relevant evidence

06

Case management & incident response systems

  • DFIR-IRIS
  • TheHive
  • Cortex
  • OpenCTI
  • VirusTotal
  • Jira
  • osTicket

Client situation

Alerts are investigated in chat threads and spreadsheets, with no central case history or IOC tracking.

Proposed scope

Set up an investigation workspace, alert-to-case sync, IOC tracking, enrichment and analyst triage workflow.

Deliverables

  • Configured case platform
  • Alert-to-case integration
  • Triage workflow notes
  • Analyst guidance

    07

    Cloud security monitoring & ingestion

    • AWS CloudTrail
    • AWS GuardDuty
    • AWS EC2
    • Azure
    • Terraform
    • Ansible

    Client situation

    Your cloud accounts generate audit logs that nobody is watching.

    Proposed scope

    Ingest cloud audit logs into your SIEM, detect IAM privilege escalation and risky changes, and monitor cloud infrastructure. Cloud resources are provisioned with Terraform and configured at scale with Ansible.

    Deliverables

    • Ingestion configuration
    • Cloud detection rules
    • Validation results
    • Recommendations

    Relevant evidence

    08

    WazuGuardix Wazuh training, seminars & workshops

    • Wazuh labs
    • Decoders & rules
    • OpenSearch dashboards
    • SOC automation

    Client situation

    Your team, students, or employees need practical, understandable Wazuh and cybersecurity learning.

    Proposed scope

    Hands-on Wazuh labs, SIEM architecture walkthroughs, custom decoders/rules, threat detection labs, seminars and awareness talks with an agreed agenda.

    Deliverables

    • Session outline
    • Lab or presentation materials
    • Live Q&A

    Relevant evidence

    Capabilities

    Broader context.

    Wazuh is the main specialization. Other areas are supported by hands-on labs and published walkthroughs.

    SIEM engineering
    Monitoring integrations, configuration, and security visibility.
    Detection engineering
    Event analysis, custom detections, and behavioral investigation.
    SOC automation
    Alert routing, ticketing, notifications, Python, and n8n workflows.
    Cloud security
    AWS and Azure experience, plus a published Google Cloud lab.
    Threat modeling
    STRIDE, architecture review, and OWASP Threat Dragon.
    Education
    Lab guides, mentoring, and community sessions.