Wazuh SIEM integration
Building operational SIEM alerting and integrations around Wazuh, with Telegram first and TheHive as the incident-response path.
tech.wired.brains.dev — cybersecurity · infrastructure · integration
A public engineering lab for real infrastructure and cybersecurity work — deployments, integrations, experiments and practical notes built from systems I operate, troubleshoot and improve.

[email protected]:~$ cat /etc/twb-mode
engineering_lab :: cybersecurity + infrastructure
[email protected]:~$ ls ~/focus
projects/ labs/ knowledge/ integrations/ source/
[email protected]:~$ systemctl status lab
● active — documenting what I build, break, fix and learn
$ find ~/labs -maxdepth 2 -type project
Private deployment of the open-source Crucix platform. The lab explores how external intelligence can be combined with infrastructure telemetry and security tooling. Runtime access remains private while the integration is designed safely.
open lab →Building operational SIEM alerting and integrations around Wazuh, with Telegram first and TheHive as the incident-response path.
Conditional Access, MFA strategy, sign-in analysis and security hardening for hybrid Microsoft identity environments.
Graylog, Grafana, Prometheus, InfluxDB and related telemetry used together to understand what infrastructure is actually doing.
$ cat /etc/lab-purpose
Tech.Wired.Brains.dev is deliberately separate from the professional portfolio. The .com explains who I am and the work I have delivered; this site is where the engineering becomes visible.
The first focus is cybersecurity and infrastructure integration: connecting telemetry, security operations, networking, identity, observability and external intelligence into systems that are useful in practice.
$ pkg list --lab
[email protected]:~$ cat links.txt
The engineering lab evolves continuously. Public source lives on GitHub; the professional portfolio, CV and contact details remain on Tech.Wired.Brains.com.