Wazuh + TheHive + Shuffle SOAR
Security Automation · Public summary
A personal lab for alert enrichment and structured security case creation.
Technologies: Wazuh · TheHive · Shuffle · VirusTotal · Windows · Linux
Objective
Explore the flow from a security alert to a documented analyst investigation.
Implementation
Used Wazuh alerts and Shuffle workflows to extract indicators, query VirusTotal and prepare TheHive cases. Explored human approval as part of a response workflow.
Lessons
Automation should preserve evidence, provide context to analysts and avoid unapproved remediation.