The eye does not close.
Home of SOC Stack: one command stands up a full open-source Security Operations Center on a single Proxmox host. The rest of Lidless Labs is the instrument rack around it: SIEM, IDS, threat intel, network, and homelab tools that a shell, a cron job, or an AI client can query under pressure. Local-first, open source, no telemetry.
- SOC Stack - Wazuh, TheHive, Cortex, MISP, Zeek, and Suricata, plus dashboards and their MCP servers, wired together on one Proxmox host in a single non-interactive run.
Detection, triage, and case work, plus the MCP servers that back a live SOC.
- wazuh-mcp - Wazuh SIEM/XDR: alerts, agents, vulnerabilities, and rules.
- misp-mcp - MISP threat intelligence: IOC lookups, correlation, and exports.
- suricata-mcp - Suricata IDS/IPS EVE JSON alert analysis and rule workflows.
- thehive-mcp - TheHive incident response: cases, alerts, tasks, and observables.
- cortex-mcp - Cortex analyzers and responders for observable analysis.
- mitre-mcp - MITRE ATT&CK mapping, group profiling, and detection-gap analysis.
- zeek-mcp - Zeek + Suricata NSM log querying and correlation.
- hotwash - SOC playbook parser with mermaid diagrams and Wazuh alert ingestion.
Turn indicators, feeds, and graphs into answers instead of open tabs.
- cyberbrief - AI threat-intel briefings with BLUF reports and ATT&CK mapping.
- intel-workbench - Structured analytic techniques: ACH matrices and STIX export.
- maltego-mcp - Maltego graph authoring and OSINT lookups for whois, DNS, and ASN.
- vervet - Threat hunting for Zeek and Suricata logs with per-host risk scoring.
Watch what changed on the wire: configs, ports, topology, and alerts.
- librenmsctrl - LibreNMS devices, ports, alerts, acknowledgements, and maintenance windows.
- n8nctrl - n8n workflow inspection, validation, execution, and ops automation.
- watchtower - NOC dashboard with interactive topology and LibreNMS/Proxmox integration.
- portgrid - Switch-port visualization for LibreNMS with color-coded views and search.
- cutsheet - Network change intelligence: watches device configs and tells you what changed.
- eero-cli - CLI for the eero mesh API with non-interactive auth and device filtering.
Operate the boxes you already run without handing an agent the keys.
- proxmox-mcp - Proxmox VE inventory and safe-write VM, container, and node operations.
- adguardctrl - AdGuard Home DNS filtering across read, safe-write, and destructive tiers.
- immichctrl - Immich photo library search, albums, people, and duplicate workflows.
- jellyctrl - Jellyfin playback sessions, library scans, and user admin.
- proxguard - Proxmox security auditor with CIS benchmarks and remediation scripts.
- samba-ad-migration - Windows AD to Samba file-share migration scripts for Proxmox.
Stand up the whole lab on a Proxmox host:
curl -sSL https://raw.githubusercontent.com/lidless-labs/soc-stack/main/install.sh | sudo bashOr browse the watch floor at lidless.dev and start with the tool that matches the system you already run.
