← RETURN TO CITADEL

♜ SIEM SANDBOX

LOG AGGREGATION · EVENT REVIEW · SECURITY VISIBILITY · SENTINEL ROADMAP

STATUS: PLANNED MODULE

PROJECT SNAPSHOT

STATUS

Planned

ROLE

Security event visibility

FOUNDATION

Auth Monitor · Fail2Ban · Linux logs

FUTURE STACK

Logs · Dashboards · Alerts · Detection logic

PROJECT OVERVIEW

The SIEM Sandbox will become the security event review layer of The Citadel. Its purpose is to collect, organize, and visualize security-relevant activity from Linux logs, SSH events, Fail2Ban activity, and future monitoring sources.

This page currently documents the planned direction for transforming raw authentication and system logs into searchable security intelligence.

PLANNED DATA SOURCES

FUTURE ARCHITECTURE

Linux Logs

Auth Monitor

SIEM Sandbox

Sentinel Detection Logic

Security Dashboard / Alerts

NEXT OBJECTIVES

Citadel Project Switchboard

Module Links Active
01 //
Linux Hardening
SSH, UFW, Fail2Ban, permissions, and operating guardrails.
Open Module →
02 //
Cloudflare Tunnel
Secure public access without exposing the VM directly.
Open Module →
03 //
Docker Lab
Containerization practice, deployment notes, and recovery workflows.
Open Module →
04 //
Auth Monitor
Authentication visibility and login monitoring foundation.
Open Module →
05 //
SIEM Sandbox
Security monitoring lab and future detection engineering space.
Open Module →
06 //
Auto Deploy
Automation pipeline for future repeatable deployment workflows.
Open Module →
07 //
Odysseus
AI assistant prototype, RAG memory core, and hardware roadmap.
Open Module →
08 //
B-MAK
Private operations case study using sanitized public-safe data only.
Open Module →