SecureInsight · EDR + AI

Project · detection

Turns raw Wazuh EDR events into analyst-ready triage summaries, cached so repeated alerts cost nothing.

Analysts drown in raw alerts

EDR produces high volumes with little context. Most analyst time goes to triaging noise instead of investigating.

The model writes the context; the analyst decides

A Python pipeline normalises Wazuh events and asks an LLM for a summary, suspected cause and next step. Repeated alert patterns resolve from a SQLite cache; user feedback suppresses known-benign repeats with a stated reason.

React dashboard follows the triage flow: what happened, why it matters, what to do next.

Validated with scripted brute-force, SQL-injection and DDoS simulations.