gensecaihq/Wazuh-Autopilot

Agentic SOC for Wazuh built on Strands Agents: a 13-agent swarm with 37 Wazuh-verified skills triages, investigates and plans response through the Wazuh MCP Server. Policy-gated autonomy, approvals, RBAC, audit, tracing and evals in one Docker stack. Bedrock, Anthropic, NVIDIA NIM, vLLM, LiteLLM or air-gapped Ollama.

57Stars on the repository
37Mods indexed here, across every type
2d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

swarm-coordination

25

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Route SOC work across the agent swarm — decide which specialist handles a case next, write a complete handoff message, and stop cleanly; use whenever you are the commander or must decide who acts next.

not rated 57 +2 2d ago A 46 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Assess possible threat-actor or campaign links using the Diamond Model and ATT&CK group data, expressed with calibrated estimative language; use only when a case shows enough TTP or infrastructure overlap to justify attribution discussion.

not rated 57 +2 2d ago A 50 tokens original MIT

threat-hunting

27

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Run hypothesis-driven threat hunts over Wazuh data using the PEAK framework (hypothesis, baseline, model-assisted), record outcomes, and hand confirmed patterns to detection engineering; use for scheduled hunts or when asked to look for undetected activity.

not rated 57 +2 2d ago A 54 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Prioritize Wazuh vulnerability-detector findings with CISA KEV, FIRST EPSS, CVSS and asset context into CISA SSVC decisions and remediation SLAs; use for vulnerability sweeps, CVE alerts or patch-priority questions.

not rated 57 +2 2d ago A 57 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

How Wazuh active response actually works — commands, agent-side scripts, dispatch vs execution, permanence, blast radius, pre-checks and verification caveats — for planning and verifying containment; use before proposing or verifying any response action.

not rated 57 +2 2d ago A 53 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Interpret Wazuh cloud and container alerts — AWS (CloudTrail, GuardDuty, VPC Flow, Security Hub), Azure, GCP, Microsoft Graph, Office 365, GitHub and Docker — with their key fields, normal baselines and pivots; use for any alert from a cloud or container integration.

not rated 57 +2 2d ago A 70 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Investigate Wazuh File Integrity Monitoring (syscheck) alerts — file and registry add/modify/delete events, checksums, permissions and who-data — separate tampering from routine change and pivot to processes and users; use for any syscheck alert or suspected persistence/tampering.

not rated 57 +2 2d ago D 65 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Interpret Wazuh malware signals — rootcheck, VirusTotal and ClamAV integrations, Microsoft Antimalware events, Sysmon detections and suspicious binaries — and turn them into enrichment and containment hand-offs; use for any malware, rootkit or suspicious-binary alert.

not rated 57 +2 2d ago A 63 tokens original MIT

wazuh-mcp-querying

33

gensecaihq/Wazuh-Autopilot

Skill Claude Code

How to query Wazuh through the Wazuh MCP Server efficiently and correctly — which tool answers which question, parameter syntax and pitfalls, result format, truncation, token budget and error handling; load before your first Wazuh query in a run.

not rated 57 +2 2d ago A 60 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Keep the Wazuh platform trustworthy — agent connectivity and version drift, manager and cluster health, event queue flooding and dropped events, silent log sources, FIM capacity and rule/decoder errors — and raise detection blind spots as cases; use for the scheduled platform health check or whenever data looks…

not rated 57 +2 2d ago A 66 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Read Wazuh alerts correctly — alert anatomy, the 0–15 level scale, composite and correlation rules, compliance and MITRE tags, decoders, custom rules and noise tuning; use when interpreting what a rule really means or when proposing rule changes.

not rated 57 +2 2d ago A 62 tokens original MIT

wazuh-sca-hardening

36

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Use Wazuh Security Configuration Assessment (SCA) results — CIS policy scores, failed checks and regressions — to prioritize hardening and map it to CIS Controls, PCI DSS and ISO 27001; use for hardening reviews, compliance evidence, or when a vulnerability or incident points to a misconfiguration.

not rated 57 +2 2d ago A 71 tokens original MIT

gensecaihq/Wazuh-Autopilot

Skill Claude Code

Interpret Wazuh Windows EventChannel and Sysmon alerts — logon, privilege, account and service events, Sysmon detection groups, field paths and logon types — mapping Windows Event IDs to Wazuh rules; use for any Windows or Sysmon alert and for Windows-focused hunts.

not rated 57 +2 2d ago A 67 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: