Libor Štrohalm - site currently WIP

Detection Engineering | SIEM | Wazuh

About

I work in cybersecurity and security monitoring, focusing on SIEM such as Wazuh. This site documents practical implementations, experiments, and lessons learned from real-world security scenarios.

Blog

Wazuh: From Nothing to Production

Architecture overview, deployment strategy, and key operational lessons.

Wazuh × Suricata

Integrating network detection into SIEM and reducing alert noise.

Wazuh Automation & MCP Server

Exploring automation and external enrichment workflows.

Projects

Wazuh Active Response Toolkit

Automation scripts for incident response and alert handling.