Services · Wazuh · SIEM · SOC automation
Security engineering that makes your SOC actually work.
Pick a service, fill a short form, and it reaches me directly on WhatsApp or email. Scope and terms are agreed before any work begins.
Choose a service
- 01Wazuh SIEM architecture & detection engineering
- 02ELK & OpenSearch stack engineering
- 03Enterprise SIEM & multi-platform log engineering
- 04SOC workflow automation & SOAR pipelines
- 05Endpoint telemetry & behavioral detection
- 06Case management & incident response systems
- 07Cloud security monitoring & ingestion
- 08WazuGuardix Wazuh training, seminars & workshops
01
Primary specializationWazuh SIEM architecture & detection engineering
- Wazuh
- Wazuh FIM/SCA
- OpenSearch
- Ansible
- AWS EC2
- Linux
- Windows
Client situation
You need a reliable Wazuh foundation: deployed correctly, tuned for your environment, and producing alerts you can trust.
Proposed scope
Wazuh Manager, Indexer, Dashboard and agent deployment (Linux, Windows, AWS), FIM, SCA, vulnerability detection, custom XML decoders and rules, and tenant separation where needed.
Deliverables
- Architecture & configuration summary
- Custom decoders and rules
- Agent onboarding checklist
- Validation results and operating notes
Relevant evidence
02
ELK & OpenSearch stack engineering
- Elasticsearch
- Logstash
- Kibana
- OpenSearch
- Wazuh
- Kafka
Client situation
Your Elasticsearch cluster is slow, mappings are messy, or logs are not flowing the way your team needs.
Proposed scope
Elasticsearch, Logstash and Kibana (or OpenSearch) deployment and tuning: index lifecycle management, mapping and template design, ingestion pipelines, dashboards, and Wazuh integration.
Deliverables
- Stack architecture & sizing notes
- Ingestion pipelines and mappings
- Kibana/OpenSearch dashboards
- Retention and tuning guidance
Relevant evidence
03
Enterprise SIEM & multi-platform log engineering
- Splunk
- IBM QRadar
- Microsoft Sentinel
- ELK/Elastic
- OpenSearch
- Grafana
Client situation
Important logs are missing, alerts lack context, or detections across your SIEM need review and tuning.
Proposed scope
Log ingestion and parsing for selected sources, field validation, event correlation, detection rule tuning, false-positive reduction, and dashboard views.
Deliverables
- Integration notes
- Detection logic and tuning changes
- Test cases and observed results
- Prioritized recommendations
Relevant evidence
04
SOC workflow automation & SOAR pipelines
- n8n
- Shuffle
- Python
- Webhooks
- Slack
- Jira
- MCP
Client situation
Analysts repeatedly copy alert details into tickets or notify teams manually.
Proposed scope
Design and implement agreed alert routing, severity-based escalation, automatic ticket/case creation, and team notifications.
Time savings are only discussed after measuring your current baseline.
Deliverables
- Workflow diagram
- Configured automation
- Validation notes
- Maintenance guidance
Relevant evidence
05
Endpoint telemetry & behavioral detection
- Sysmon
- Auditd
- CrowdStrike
- Suricata
- YARA
- MITRE ATT&CK
Client situation
You lack visibility into what actually happens on endpoints and the network: process abuse, LOLBins, suspicious files.
Proposed scope
Sysmon and Auditd telemetry design, behavioral detections mapped to MITRE ATT&CK, YARA file scanning, and network inspection with Suricata.
Deliverables
- Telemetry configuration
- Behavioral detection rules
- MITRE ATT&CK mapping
- Test results
Relevant evidence
06
Case management & incident response systems
- DFIR-IRIS
- TheHive
- Cortex
- OpenCTI
- VirusTotal
- Jira
- osTicket
Client situation
Alerts are investigated in chat threads and spreadsheets, with no central case history or IOC tracking.
Proposed scope
Set up an investigation workspace, alert-to-case sync, IOC tracking, enrichment and analyst triage workflow.
Deliverables
- Configured case platform
- Alert-to-case integration
- Triage workflow notes
- Analyst guidance
07
Cloud security monitoring & ingestion
- AWS CloudTrail
- AWS GuardDuty
- AWS EC2
- Azure
- Terraform
- Ansible
Client situation
Your cloud accounts generate audit logs that nobody is watching.
Proposed scope
Ingest cloud audit logs into your SIEM, detect IAM privilege escalation and risky changes, and monitor cloud infrastructure. Cloud resources are provisioned with Terraform and configured at scale with Ansible.
Deliverables
- Ingestion configuration
- Cloud detection rules
- Validation results
- Recommendations
Relevant evidence
08
WazuGuardix Wazuh training, seminars & workshops
- Wazuh labs
- Decoders & rules
- OpenSearch dashboards
- SOC automation
Client situation
Your team, students, or employees need practical, understandable Wazuh and cybersecurity learning.
Proposed scope
Hands-on Wazuh labs, SIEM architecture walkthroughs, custom decoders/rules, threat detection labs, seminars and awareness talks with an agreed agenda.
Deliverables
- Session outline
- Lab or presentation materials
- Live Q&A
Relevant evidence
Capabilities
Broader context.
Wazuh is the main specialization. Other areas are supported by hands-on labs and published walkthroughs.
- SIEM engineering
- Monitoring integrations, configuration, and security visibility.
- Detection engineering
- Event analysis, custom detections, and behavioral investigation.
- SOC automation
- Alert routing, ticketing, notifications, Python, and n8n workflows.
- Cloud security
- AWS and Azure experience, plus a published Google Cloud lab.
- Threat modeling
- STRIDE, architecture review, and OWASP Threat Dragon.
- Education
- Lab guides, mentoring, and community sessions.