Building a Practical Wazuh Home SOC Lab
Step-by-step guide to deploying Wazuh, OpenSearch, and Suricata for a fully functional security operations center.
Read on Medium →Gain real-time visibility into cyber threats and automate incident response with open-source SIEM, IDS, and custom detection engineering.
Continuous log collection and real-time alerting across your infrastructure. Never miss a critical security event.
Engineered threat rules and analytics tailored to your environment. From brute-force to cloud compromise.
Deploy and manage Wazuh, Suricata, and OpenSearch stacks without vendor lock-in or hidden costs.
NcryptoEdge is a cybersecurity initiative focused on Security Operations, Threat Detection, and Incident Response. We help organizations strengthen their defenses by building practical SOC labs, engineering custom detections, and performing threat investigations.
Our mission is to improve visibility and accelerate response to attacks. We deploy SIEM systems (Wazuh/OpenSearch), integrate IDS (Suricata) alerts, and enforce security best practices through hands-on research and open-source tooling.
Custom-engineered detection rules for real-world attack scenarios. Each detection is documented, tested, and open-sourced.
Alerts on repeated SSH login failures from the same source IP, identifying credential-guessing attacks against your infrastructure.
View on GitHub →Detects Nmap and stealth port scans via Suricata IDS logs. Identifies reconnaissance behavior before exploitation begins.
View on GitHub →Flags obfuscated and encoded PowerShell commands using Wazuh agent events. Catches living-off-the-land techniques.
View on GitHub →Triggers on indicators of malicious executable downloads via honeypot feeds and hash reputation checks.
View on GitHub →Monitors unusual AWS CloudTrail login patterns for potential account compromise and unauthorized access.
View on GitHub →Enterprise-grade security services built on open-source foundations. Coming soon as NcryptoEdge scales.
Continuous log collection, real-time alerting, and SOC dashboard management. We watch your perimeter so you do not have to.
Rapid analysis, containment, and remediation of detected threats. From alert to action in minutes, not hours.
Proactive adversary detection across your environment. We search for what automated rules might miss.
Identification of configuration flaws, exposure gaps, and compliance deviations before attackers find them.
A cybersecurity professional specializing in detection engineering and SOC operations. With hands-on experience deploying enterprise SIEM/IDS stacks and conducting threat hunts, Keslee builds practical lab environments to tackle real-world attacks.
Passionate about open-source security, sharing research and tools publicly through GitHub and the NcryptoEdge Medium blog. Dedicated to helping organizations defend against evolving threats through automation, visibility, and engineering excellence.
Security research, lab buildouts, and detection engineering write-ups published on Medium.
Step-by-step guide to deploying Wazuh, OpenSearch, and Suricata for a fully functional security operations center.
Read on Medium →Integrating network intrusion detection with SIEM correlation rules for real-time threat visibility.
Read on Medium →Connecting AWS CloudTrail, GuardDuty, and open-source tooling for unified cloud threat detection.
Read on Medium →Ready to strengthen your security posture? Reach out for collaborations, consulting, or just to talk shop.
Whether you need detection engineering support, SOC lab guidance, or want to collaborate on security research, we are here to help.