Hivewire
Automated Threat Detection & Response System
A SOC-in-a-box that goes from raw security alert to AI-assessed response recommendation in under a minute.
- Wazuh SIEM stack across a multi-machine lab, with real-time log collection from Windows and Linux hosts.
- Automated enrichment pipeline: pulls alert details, checks threat intel (VirusTotal, NVD), opens a TheHive case, and notifies via email and Slack — all in under 10 seconds.
- Wazuh
- Docker
- Python
- FastAPI
- Claude SDK
- MCP
- Slack
- TheHive
- MITRE ATT&CK
- NIST 800-61