active-response
Here are 13 public repositories matching this topic...
Enterprise-grade Wazuh SIEM/XDR + TheHive IRP deployment on WSL2 and Docker: detection engineering, MITRE ATT&CK mapping, automated active response, SOC dashboards & incident case management. Full SOC pipeline across 9 phases.
-
Updated
Apr 15, 2026
Command-line interface for the Wazuh REST API - agents, alerts, vulnerabilities, active response and live TUI dashboard
-
Updated
May 7, 2026 - Go
A collection of Python utilities and build artifacts used to package and sign small Windows helper applications for interacting with Wazuh and endpoint workflows. This repository contains tools for isolation handling, application registration, threat removal helpers, and desktop notifications.
-
Updated
Jan 8, 2026 - Python
Active Response for Cloudflare API
-
Updated
Apr 11, 2025 - Python
Enterprise Wazuh SIEM configuration with VirusTotal & MISP threat intelligence, OPNsense & MikroTik monitoring, automated active responses, Telegram SOC alerts, custom decoders/rules, and a Dockerized syslog collector. Includes MITRE ATT&CK mappings and ready-to-import dashboards.
-
Updated
Apr 8, 2026 - Python
Complete Wazuh YARA configuration guide
-
Updated
May 7, 2026
Network Intrusion Detection with Suricata integrated into Wazuh SIEM
-
Updated
May 7, 2026
SOC Automation Project (Wazuh, TheHive and Shuffle)
-
Updated
Jul 2, 2025
This SOC semi-automation project integrates Wazuh, Shuffle, IRIS, MISP, Google Chat, and Grafana to handle and respond security incidents targeting DVWA on both Windows and Ubuntu. Goals: to execute automated security workflows for event collection, alert escalation, and incident response based on administrator decisions.
-
Updated
Feb 9, 2026 - Python
Enterprise SIEM implementation using Wazuh with FIM, YARA malware detection, and automated Active Response
-
Updated
May 7, 2026
MODINE IDEAL: A High-Performance Cyber Defense & Intelligence Ecosystem. Engineered for proactive Threat Hunting, Zero-Day detection, and Automated Incident Response. Leveraging Wazuh and MITRE ATT&CK mapping to transform passive monitoring into an active security stronghold.
-
Updated
Feb 26, 2026
Wazuh Active Response Script to Add IP to `ipset` List
-
Updated
May 8, 2026 - C
Improve this page
Add a description, image, and links to the active-response topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the active-response topic, visit your repo's landing page and select "manage topics."