Origin story · Wazuh, and everything since

We started with Wazuh. Then we built the decision layer above it — and above everything else you run.

Wazuh is a superb free detection agent and a hard place to run a SOC from. Its alerts are honest, its rules are open, its ingest costs nothing — and then a person has to turn thousands of rows into a decision. Seculogik is what that person needed: a small number of qualified cases, a queue that says what to open next, and an AI analyst that shows its work. Wazuh stays exactly where it is. So does any other source you point at us.

Chapter one

The beachhead, not the foundation.

Our free edition is Wazuh-only by design: alerts, cases, the analyst screens, notifications and administration, fed by your Wazuh manager and indexer and nothing else. It is complete, it is self-hosted, and you can run it forever. It is also how most teams meet us.

Building on Wazuh first taught us what every SOC actually needs: an alert that arrives already rated, an asset that resolves to a client, vulnerability findings that land in an operations centre rather than a spreadsheet, and detection content that knows its own MITRE coverage. Those lessons became the platform — and the platform does not care where the alert came from.

Source-agnostic by design

Seculogik sits above whatever detection stack you already run. Open-source SIEM and data stacks: Wazuh, OpenSearch, Elastic / ELK, ClickHouse. Market platforms: Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Fortinet and more. And if your source is not on the list, we build the connector — or you push events through the generic webhook and map them once in the universal data map.

Chapter two

What Wazuh cannot do — and was never meant to.

  • Correlate across sources and time. A rule fires on one event. A campaign is many events, across EDR, identity and firewall, over days. Nobody on your team has time to stitch them together by hand.
  • Hold a case. Wazuh has alerts. It has no lifecycle, no SLA, no assignee, no decision trace, no record of what would have changed the verdict — nothing you can hand to an auditor.
  • Separate clients. One manager, one flat alert stream. An MSSP needs one case space per client, enforced rather than promised.
  • Absorb bursts. A single rule firing hundreds of times in a few minutes is hundreds of rows, not one incident — and the incident is what you need to see.
  • Respond with approval. Active response is a script. A SOC needs a workflow that pauses for a person before isolating a host.
  • Explain itself to a committee. A dashboard is not a report with a methodology, and your board and your regulator will ask for one.

None of this is a criticism of Wazuh. It is the gap between detection and decision — and it is the same gap on Elastic, Splunk or Sentinel.

The next level

Wazuh, then Seculogik. Side by side.

Layer
Wazuh alone
Wazuh + Seculogik
Detection
Rules you write and tune by hand
Your rules, plus 72 shipped MITRE-mapped detection packs you import from a screen and deploy in minutes — to Wazuh or to the SIEM you already run
Ingestion
Wazuh agents and syslog
Wazuh plus 23 vendor connectors across SIEM, EDR, cloud, network, email, identity and ticketing; push webhooks; passive tailing of your existing SIEM; custom connectors on request
Noise
Every alert is a row
Repeats collapse, known-benign patterns are set aside, and a burst of hundreds becomes one case rated for what it really is
Correlation
None
Nine independent strategies vote on one verdict; recognised attack storylines; a kill-chain position that advances with the evidence; a readable decision trace on every case
Cases
None
A full lifecycle, SLA clocks, capacity-based auto-assignment, and a queue that tells each analyst what to open next
Clients
One flat stream
One case space per client, enforced at several independent layers; unattributed alerts wait in quarantine rather than being guessed; white-label for your brand
Response
Active-response scripts
Workflows that pause for a person before anything destructive; remote agents that keep vendor credentials on your own hosts; tickets into ServiceNow, Jira and TheHive
Vulnerabilities
A list per agent
A Vulnerability Operations Centre: several scanners corroborated, a remediation lifecycle with due dates, a risk-acceptance register that expires, a committee-ready report
AI
None
SIROC: an AI analyst that lists hypotheses and evidence before its verdict, is checked against the case's own alerts, and runs on your box by default
Reporting
Dashboards
Case and client reports, scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, evidence packs that state their own methodology and coverage
Cost model
Free ingest
Still free ingest. No per-GB, no per-endpoint, no per-tenant SaaS fee. You pay for the decision layer, never for your own logs

The right-hand column reads the same whatever feeds it. Swap Wazuh for Elastic, Sentinel or a custom connector and nothing on the right changes.

Detection content

Seventy-two packs, named for the behaviour they catch.

Active Directory abuse. Cloud audit trails across AWS, Azure and Microsoft 365. Containers and hypervisors. Databases and email. Endpoint telemetry from CrowdStrike and SentinelOne. Identity providers such as Okta. Intrusion detection. Linux privilege and persistence. Network appliances from Fortinet, Palo Alto, Cisco, pfSense, Check Point and Sophos. Supply-chain compromise. Web servers and CMS. Windows Sysmon, PowerShell and the scheduled-task tricks attackers still rely on.

Every pack is mapped to MITRE ATT&CK, so the coverage matrix in the product shows what is actually deployed — not what a spreadsheet says. Independent research puts the average enterprise SIEM at 21% of ATT&CK techniques detected while the data already ingested could cover 90% (CardinalOps, 2025). Shipped content is how you close that gap on day one instead of rule by rule.

72
Detection packs
MITRE-mapped · importable from a screen
23
Vendor connectors
plus Wazuh, webhooks and custom connectors
1
Box
VPS or on-prem · no GPU · installs in minutes
Total cost of ownership

No ingest tax. Your log volume never drives your bill.

Most SIEM and XDR vendors charge per gigabyte, per event or per asset for the privilege of putting your own logs in. Seculogik ingests through Wazuh — or through the SIEM you already own — so volume is not a meter. Your cost is one box, the people who run it, and a licence quoted per deployment and per year.

Gartner puts it plainly: SIEM buyers “have grown increasingly frustrated by SIEM cost bloat”. Our pricing page sets editions and add-ons beside the public list prices of the usual suspects. Where ingest is already cheap for you — a Microsoft E5 estate, say — we compete on sovereignty and the MSSP model, not on raw price.

the three-line pitch
  1. No ingest tax. Your log volume doesn't drive your bill.
  2. Sovereign. Data and AI stay on your infrastructure, and cloud AI is a switch you own.
  3. MSSP-native. Multi-client and white-label from day one. You bill your clients; we don't bill your volume.
Already on Wazuh?

Point us at your manager. Keep everything.

Start free with the Wazuh-only edition, or book a thirty-minute session and we replay a week of your own alerts through the correlation engine — from Wazuh, or from whatever you run today.