{"repo":"BeardedTinker/wazuh-homelab-security","free":true,"listed":false,"github":"https://github.com/BeardedTinker/wazuh-homelab-security","clone":"git clone https://github.com/BeardedTinker/wazuh-homelab-security.git","description":"Practical Wazuh rules and decoders for homelab security (UniFi, Synology DSM, Home Assistant)","language":"Shell","stars":32,"topics":["home-assistant","homelab","siem","synology","unifi","wazuh"],"license":null,"category":"self-hosted-apps","readme_excerpt":"Wazuh Homelab Security Detection rules and decoders used in the BeardedTinker homelab SIEM setup. Practical Wazuh rules, decoders, sample logs, and dashboard building blocks for a real homelab setup. This repository focuses on three common homelab telemetry sources: - UniFi firewall / IDS / IPS events - Synology DSM authentication events - Home Assistant security-relevant logs via Wazuh Agent + journald The goal is simple: detect real security signals in a homelab without introducing enterprise-only complexity. This repository reflects a real working homelab deployment. --- What this repo covers UniFi Detection ideas currently implemented: - WAN LOCAL firewall drops - SSH probes - Synology DSM exposure attempts - Home Assistant exposure attempts - HTTP / HTTPS background probing - high-rate repeated probes from the same source - UniFi CEF IDS / IPS event parsing - IDS targeting SSH management services - IDS targeting HTTPS management services - IDS targeting Home Assistant - IDS targeting Synology DSM - repeated IDS targeting of Home Assistant - repeated IDS targeting of Synology DSM - reconnaissance / multi-service probing detection --- Synology DSM Detection ideas currently implemented: - login success - login failure - repeated login failures from the same IP - success after multiple failures from the same IP and user --- Home Assistant Detection ideas currently implemented: - invalid authentication from http.ban - repeated invalid authentication from the same IP - suspici","default_branch":null,"files":null,"tree":[],"storefront":"/r/BeardedTinker","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/BeardedTinker/wazuh-homelab-security/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}