MeyyappanVenkatesh/Open-Source-SIEM-XDR-SOAR-Integration ? reverse-engineered prompt
Reverse engineered prompt
Build me a small cybersecurity lab project that shows how SIEM, XDR, IDS, and SOAR can work together for real time threat detection and automated response.
I want it to use Wazuh for log collection and alerting, Suricata for network intrusion detection, Shuffle for automated response playbooks, and VirusTotal for threat lookup. The goal is to simulate common attacks like port scans, SSH brute force, malware detection, ransomware style file changes, suspicious commands, and possible data exfiltration, then automatically respond by blocking IPs, quarantining files, disabling access, and sending clear alerts.
Please set it up so it feels like a working capstone demo with configuration files, helper scripts, and screenshots or placeholders for proof of the tests. Keep it practical for a small business style lab, and make sure the instructions are easy to follow so someone can import the virtual machines, connect everything on the same network, and run the simulations. If you need current setup details, look up the latest docs online.
Are you gonna build this?
make sure you review the code using coderabbit