Flagship Project • Security & Threat Detection
IT Security Infrastructure
Integrated security operations stack for monitoring, case handling, automation, and threat-intelligence sharing.
Workflow Illustration
This stack connects security operations that would otherwise stay siloed across separate consoles. Alert ingestion, workflow automation, case handling, and threat-intelligence context become easier to follow when the response chain is structured from detection through resolution.
Business Problem
Security monitoring, automation, case handling, and threat-intelligence workflows lose effectiveness when each function lives in disconnected tooling.
My Contribution
Structured a more coherent internal stack around Wazuh, Shuffle, Iris, and MISP to improve visibility, response workflow structure, and security operations readiness.
Operational Flow
- Security telemetry and alerts are ingested into a more unified monitoring context.
- Automation workflows help enrich and route alert handling faster.
- Case handling supports investigation and response tracking in a more structured process.
- Threat-intelligence context strengthens incident review and prioritization.
Key Capabilities
- SIEM-oriented visibility with Wazuh.
- SOAR automation flow with Shuffle.
- Case handling support with Iris.
- Threat-intelligence sharing context with MISP.
Current Status
Status: Integrated internal security workflow focused on connecting monitoring, automation, case handling, and intelligence context into one clearer SOC operating model.
Privacy note: environment details, access endpoints, and security-sensitive configuration are excluded.