MechabitsMechabits
Back to work
DefyRax

2026 · Cybersecurity · SOC platform

DefyRax

Client: Mechabits

Raw logs in, investigated incidents out — a SOC platform that ingests Wazuh, Splunk, Windows, and Linux logs, correlates alerts into cases, and routes them to the right analyst.

Overview

DefyRax is a security operations platform built to turn raw log noise into investigated incidents. It ingests security logs from Wazuh, Splunk, Windows, and Linux, applies threshold and Sigma detection rules, and correlates related alerts into cases automatically. Indicators of compromise are enriched without analyst effort, and each case is routed to the right analyst inside a scoped workspace. The SOC dashboard tracks open alerts, cases, SLA breaches, and MTTD/MTTR at a glance, with severity breakdowns, case-status views, and MITRE ATT&CK technique mapping. VIRA — the built-in virtual intelligence and response analyst — summarizes case timelines, suggests IOC lookups, and proposes the next investigative step right on the dashboard.

Challenge

SOC teams drown in raw alerts from mixed sources — without correlation, enrichment, and ownership, real incidents hide in noise and response times slip.

Solution

An end-to-end pipeline: multi-source log ingestion, threshold and Sigma rules, automatic alert-to-case correlation, IOC enrichment, analyst routing in scoped workspaces, SLA/MTTD/MTTR tracking, MITRE ATT&CK mapping, and an AI analyst (VIRA) that summarizes and suggests next steps.

Results

  • Multi-source ingestion: Wazuh, Splunk, Windows, and Linux logs in one pipeline
  • Alerts correlated into cases with automatic IOC enrichment and analyst routing
  • SOC dashboard with SLA, MTTD/MTTR, severity, and MITRE ATT&CK visibility — plus VIRA, the built-in AI analyst

Stack

SIEM ingestionWazuhSplunkSigma rulesMITRE ATT&CKIOC enrichmentAI analystNext.jsTypeScript