Skip to content
All projects & labs

Detection Lab

Anomaly detection with Wazuh and Elastic

A simulated SOC workflow using external machine learning to identify unusual activity and visualize findings.

WazuhElasticMachine learningDashboards

Why this matters to a team

Rule-based alerts catch known patterns; looking for unusual behavior is one way to explore what rules might miss.

Problem

Static detection rules can miss activity that does not match a known signature. This lab explored adding an anomaly-focused view to a Wazuh workflow.

Documented approach

  1. 01Collect security events in a simulated SOC environment.
  2. 02Pass selected data to an external machine-learning step to flag unusual activity.
  3. 03Visualize findings for review.

My contribution

Built and publicly described the simulated workflow as a personal project on LinkedIn.

Evidence

Limitations

This is a simulated lab. The linked repository contains supporting log material, not a verified complete implementation. No model accuracy or benchmark figures are claimed.