Detection Lab
Anomaly detection with Wazuh and Elastic
A simulated SOC workflow using external machine learning to identify unusual activity and visualize findings.
WazuhElasticMachine learningDashboards
Why this matters to a team
Rule-based alerts catch known patterns; looking for unusual behavior is one way to explore what rules might miss.
Problem
Static detection rules can miss activity that does not match a known signature. This lab explored adding an anomaly-focused view to a Wazuh workflow.
Documented approach
- 01Collect security events in a simulated SOC environment.
- 02Pass selected data to an external machine-learning step to flag unusual activity.
- 03Visualize findings for review.
My contribution
Built and publicly described the simulated workflow as a personal project on LinkedIn.
Evidence
Limitations
This is a simulated lab. The linked repository contains supporting log material, not a verified complete implementation. No model accuracy or benchmark figures are claimed.