A unified, production-grade security operations platform spanning five SIEM/NSM tools across a Proxmox VE hypervisor infrastructure. Built to provide layered visibility from network packets to endpoint process telemetry.
PostEx required enterprise-grade security visibility across a fintech environment processing high-value financial transactions. I designed and built a layered security monitoring platform that integrates five best-of-breed tools — each providing distinct, complementary visibility layers — all running on a Proxmox VE virtualization infrastructure with Docker containerization for operational flexibility.
The result: full-spectrum visibility from raw network packets (Security Onion + Suricata + Zeek) through host-level telemetry (Wazuh + Elastic Defend) to centralized log correlation and threat hunting (Splunk Enterprise + Elastic SIEM), with all components interconnected for enriched detection and automated response.
┌────────────────────────────────────────────────────────────────────┐
│ DATA SOURCES (What Generates Logs) │
├────────────────────────────────────────────────────────────────────┤
│ Windows Endpoints (500+) Linux Servers (100+) MikroTik/Cisco │
│ VMware ESXi Proxmox VMs Web Apps VPN Gateways AD/DC │
└───────┬─────────────┬─────────────┬─────────────┬───────┘
│ │ │ │
▼ ▼ ▼ ▼
┌────────────┐ ┌───────────┐ ┌────────────┐ ┌────────────┐
│SPLUNK ENT. │ │ WAZUH │ │ELASTIC FLT │ │SEC. ONION │
│ Log Index │ │ SIEM │ │ + Defend │ │Suricata │
│ SPL Rules │ │ + XDR │ │ EDR │ │Zeek/NSM │
│ Dashboards │ │ FIM/AR │ │ KQL/EQL │ │JA3/JA3S │
└────────────┘ └───────────┘ └────────────┘ └────────────┘
│ │ │
└────────────────────┬────────────────────┘
▼
┌───────────────────────────┐
│ SOC AUTOMATION (n8n) │
│ IP Enrichment (VT/AbuseIPDB) │
│ JIRA Ticket Creation │
│ Telegram Alert (MTTN <2min) │
└───────────────────────────┘
Centralized log aggregation and correlation engine. Primary threat hunting and investigation platform.
Host-level detection, file integrity monitoring, vulnerability scanning, and active response.
Endpoint security monitoring and EDR across 100+ cross-platform servers.
Network-layer visibility. Catches what endpoint tools miss: lateral movement, DNS tunneling, encrypted C2.
Virtualization platform and containerization layer hosting all security tools.
| Tactic | Technique | Splunk | Wazuh | Elastic | Sec Onion |
|---|---|---|---|---|---|
| Initial Access | T1190 Exploit Public App | ✓ | ✓ | ✓ | ✓ |
| Execution | T1059.001 PowerShell | ✓ | ✓ | ✓ | |
| Persistence | T1053.005 Sched. Task | ✓ | ✓ | ✓ | |
| Defense Evasion | T1218 LOLBin Execution | ✓ | ✓ | ✓ | |
| Credential Access | T1110.001 Brute Force | ✓ | ✓ | ✓ | ✓ |
| Lateral Movement | T1021.001 RDP | ✓ | ✓ | ✓ | |
| C&C | T1071.004 DNS Tunneling | ✓ | ✓ | ||
| Exfiltration | T1041 Exfil over C2 | ✓ | ✓ | ✓ |