SOC Operations Active

Security Operations
& Threat Detection

Gain real-time visibility into cyber threats and automate incident response with open-source SIEM, IDS, and custom detection engineering.

ncryptoedge-soc — wazuh-manager
🛡️

24/7 Monitoring

Continuous log collection and real-time alerting across your infrastructure. Never miss a critical security event.

🔍

Custom Detections

Engineered threat rules and analytics tailored to your environment. From brute-force to cloud compromise.

Open-Source SIEM

Deploy and manage Wazuh, Suricata, and OpenSearch stacks without vendor lock-in or hidden costs.

Building Defenses,
One Detection at a Time

NcryptoEdge is a cybersecurity initiative focused on Security Operations, Threat Detection, and Incident Response. We help organizations strengthen their defenses by building practical SOC labs, engineering custom detections, and performing threat investigations.

Our mission is to improve visibility and accelerate response to attacks. We deploy SIEM systems (Wazuh/OpenSearch), integrate IDS (Suricata) alerts, and enforce security best practices through hands-on research and open-source tooling.

5+ Custom Detections
3 SOC Lab Builds
100% Open Source

Tech Stack

Wazuh Suricata OpenSearch Python Sigma YARA Docker AWS Linux GitHub Actions Slack API CloudTrail

Threat Detections

Custom-engineered detection rules for real-world attack scenarios. Each detection is documented, tested, and open-sourced.

D-001

SSH Brute-Force Detection

Alerts on repeated SSH login failures from the same source IP, identifying credential-guessing attacks against your infrastructure.

Wazuh Linux
View on GitHub →
D-002

Port Scan Activity

Detects Nmap and stealth port scans via Suricata IDS logs. Identifies reconnaissance behavior before exploitation begins.

Suricata IDS
View on GitHub →
D-003

Suspicious PowerShell

Flags obfuscated and encoded PowerShell commands using Wazuh agent events. Catches living-off-the-land techniques.

Wazuh Windows
View on GitHub →
D-004

Malware Download Detection

Triggers on indicators of malicious executable downloads via honeypot feeds and hash reputation checks.

Wazuh Threat Intel
View on GitHub →
D-005

AWS Login Anomaly

Monitors unusual AWS CloudTrail login patterns for potential account compromise and unauthorized access.

CloudTrail AWS
View on GitHub →
📦

View All Detections

Explore the full detection library on GitHub

Open Repository →

MSSP-Style Offerings

Enterprise-grade security services built on open-source foundations. Coming soon as NcryptoEdge scales.

📡

24/7 Security Monitoring

Continuous log collection, real-time alerting, and SOC dashboard management. We watch your perimeter so you do not have to.

🚨

Incident Response

Rapid analysis, containment, and remediation of detected threats. From alert to action in minutes, not hours.

🎯

Threat Hunting

Proactive adversary detection across your environment. We search for what automated rules might miss.

🔐

Security Assessments

Identification of configuration flaws, exposure gaps, and compliance deviations before attackers find them.

Meet the Founder

👤

Keslee Ncrypto

Founder & Lead Detection Engineer

A cybersecurity professional specializing in detection engineering and SOC operations. With hands-on experience deploying enterprise SIEM/IDS stacks and conducting threat hunts, Keslee builds practical lab environments to tackle real-world attacks.

Passionate about open-source security, sharing research and tools publicly through GitHub and the NcryptoEdge Medium blog. Dedicated to helping organizations defend against evolving threats through automation, visibility, and engineering excellence.

Latest from the Blog

Security research, lab buildouts, and detection engineering write-ups published on Medium.

🖥️
June 2026

Building a Practical Wazuh Home SOC Lab

Step-by-step guide to deploying Wazuh, OpenSearch, and Suricata for a fully functional security operations center.

Read on Medium →
🌐
July 2026

Hands-on with Suricata IDS and Wazuh Alerts

Integrating network intrusion detection with SIEM correlation rules for real-time threat visibility.

Read on Medium →
☁️
August 2026

Integrating Cloud Security Monitoring

Connecting AWS CloudTrail, GuardDuty, and open-source tooling for unified cloud threat detection.

Read on Medium →

Let's Secure Your Edge

Ready to strengthen your security posture? Reach out for collaborations, consulting, or just to talk shop.

Get in Touch

Whether you need detection engineering support, SOC lab guidance, or want to collaborate on security research, we are here to help.

📧
Email hello@ncryptoedge.com
📱
Phone +234 907 287 1261
🐙
GitHub github.com/kesleeNcrypto
💼
LinkedIn linkedin.com/in/keslee-ncryptoedge