seim
Here are 28 public repositories matching this topic...
Notif360 is an open-source system monitoring and notification tool designed to provide comprehensive oversight of critical system metrics, website health, and malware scanning
-
Updated
Aug 28, 2025 - Shell
Enterprise-style Wazuh SIEM homelab featuring Windows & Linux monitoring, Sysmon, Auditd, custom detections, threat hunting, incident response, and MITRE ATT&CK mapping.
-
Updated
Jun 11, 2026
Hands-on SOC lab built with Wazuh, Sysmon, Suricata, VirusTotal, and Chainsaw to simulate, detect, and investigate RDP-based intrusions through SIEM monitoring, threat hunting, and incident analysis.
-
Updated
Jul 31, 2026
Splunk SIEM investigation lab with SPL detection rules, BOTS dataset analysis, and IR reports mapped to MITRE ATT&CK
-
Updated
Jun 14, 2026
Evidence-first, SIEM-agnostic AI security alert triage & investigation engine. Ingests alerts from multiple SIEM/EDR sources, deduplicates and correlates them into incidents, and produces explainable, evidence-backed AI analysis mapped to MITRE ATT&CK.
-
Updated
Sep 6, 2026 - Python
This repository stores tables for use in SEIM tools (specifically Sumologic)
-
Updated
Oct 16, 2020
Malware Analysis Lab using Wazuh & Sysmon for endpoint monitoring, threat hunting, MITRE ATT&CK mapping, and incident analysis.
-
Updated
Aug 20, 2026
My SOC Level 1 study notes from TryHackMe. Covers threat intelligence, SIEM investigations, digital forensics, endpoint monitoring, and phishing analysis, with practical labs using tools like Splunk, Wireshark, Sysmon, and Volatility.
-
Updated
May 30, 2026
Hands-on Wazuh SIEM deployment with Windows and Linux endpoints, File Integrity Monitoring (FIM), and Threat Hunting.
-
Updated
Jul 4, 2026
Educational Wazuh SOC home lab for security monitoring, alert triage, log analysis, incident response and CTI enrichment.
-
Updated
Aug 18, 2026
A self built log monitoring and alerting tool. Parses SSH auth logs with Bash and Python to detect brute force attacks and privilege escalation, renders the findings in a custom JavaScript dashboard, and ships with Splunk SPL queries for SIEM style correlation.
-
Updated
Jun 16, 2026 - HTML
Readable, RFC-compliant plain-text email alerts for Wazuh. A drop-in replacement for wazuh-maild that fixes truncated subjects, malformed headers, and messages rejected by strict MTAs for exceeding the 998-octet line limit. Single Python file, no dependencies, no external config.
-
Updated
Aug 13, 2026 - Python
CTI Lab 2 — Malicious File Analysis, ELK Stack, Purple Teaming (MITRE ATT&CK), and Elastic SIEM Alerting exercises. Tools: Sysmon, Atomic Red Team, Kibana, VirusTotal.
-
Updated
May 14, 2026
First attempt at a lambda architecture SEIM using Power BI & Azure Sentinel
-
Updated
Sep 8, 2023
Basic Intrusion Detection System using Scapy
-
Updated
Apr 4, 2026 - Python
Personal SOC lab built on Wazuh + Suricata to practice detection engineering, alert triage, and incident investigation.
-
Updated
Jul 18, 2026 - Shell
Installed and configured Splunk Enterprise, created a SOC Lab index, and prepared a SIEM environment for future log ingestion and security investigations.
-
Updated
Jul 12, 2026
Add this topic to your repo
To associate your repository with the seim topic, visit your repo's landing page and select "manage topics."