I will build automated incident response and active response rules with wazuh

Pakistan

I speak English, Hindi

13 orders completed

Cyber Security Analyst, Wazuh SIEM Specialist

3+ years of experience as a Cyber Security Engineer & active Bank SOC/CERT Analyst. I deploy, tune, and scale open-source SIEM architectures - specifically Wazuh - to build production-grade defense pi...
About this Gig

AUTOMATED INCIDENT RESPONSE WAZUH FIGHTS BACK AUTOMATICALLY


Most Wazuh setups generate alerts. But this setup will block, isolate, and respond before you even open your laptop.


I'm a SOC/CERT Analyst at a banking-sector data center. 

Automated response isn't optional where I work; it's essential.


BASIC Auto-Blocking

- RDP & SSH brute-force auto-block

- Custom Bash & PowerShell response scripts

- Email + webhook alerting


STANDARD Endpoint Defense  

- Ransomware detection via FIM triggers

- Automated host isolation (Windows & Linux)

- Slack/Telegram/Discord alerts + AbuseIPDB intel


PREMIUM SOAR-Lite Pipeline

- Wazuh TheHive auto case creation

- VirusTotal/Cortex IOC enrichment

- MITRE ATT&CK mapped playbooks


WHAT I NEED FROM YOU

  • SSH access to Wazuh manager
  • Endpoint OS types
  • Preferred alert channel


Message me first, I'll review your current setup and recommend exactly what will work best.


Device:

Desktop

Laptop

Server

Router

Operating system:

Windows

Linux

Ubuntu

My Portfolio