5 min read
Building a university SOC: Wazuh, MISP and CrowdSec
Why I built a detection-and-response stack from open-source parts instead of buying one, how the enrichment loop fits together, and two lessons that only show up once it's running in production.