SB SIEM MCP
A Model Context Protocol server that lets an LLM agent query Wazuh directly: 28 tools across 9 security domains, with the guardrails that make it safe to point at a live SIEM.
NETWORK SECURITY ENGINEER · DETECTION ENGINEER · BENGALURU
I work at the wire level, on VPN and protocol internals and OT/ICS traffic, and on the detections that fire when something on that wire goes wrong.
OT protocol security sits in both tracks, which is why most of the work below counts twice.
Open to network security and detection engineering roles · Bengaluru or remote · replies within two working days
THE WORK · 31 STARS ACROSS 3 PUBLIC REPOS
A Model Context Protocol server that lets an LLM agent query Wazuh directly: 28 tools across 9 security domains, with the guardrails that make it safe to point at a live SIEM.
29 detection rules for the five protocols that run industrial plants (Modbus, DNP3, IEC 104, MQTT and OPC-UA), mapped to MITRE ATT&CK for ICS and validated in an OpenPLC lab.
50 detection rules that carry their NIST CSF 2.0 subcategory and MITRE ATT&CK technique inside the alert itself, so compliance evidence falls out of detection instead of being reconstructed later.
A multi-AS BGP and OSPF topology built on containerlab and FRR, generated from one declarative source and checked by automated state assertions rather than by eye.
SHIPS WHENA public repo where one command builds the fabric and a second asserts converged state: adjacencies up, routes present, paths taking the intended AS hops.
A passive wire-level sensor for Modbus, DNP3 and IEC 104 that parses industrial traffic off a span port and emits events the OT Sentinel rules already know how to read.
SHIPS WHENA sensor that turns captured ICS traffic into structured logs, plus a labelled capture corpus, wired end to end into the existing OT Sentinel rule set.
THE SHORT VERSION