This repository contains a lab and detection pipeline for simulating brute-force attacks (MITRE ATT&CK T1110) against a Windows Server and analyzing Windows security events in Splunk. The project ...
An agentic Security Operations Center (SOC) automation toolkit that connects a large language model to real security tools via the Model Context Protocol (MCP). The system investigates alerts, ...