Turn Wazuh alerts into cases, plans, and safe action — automatically.
Wazuh OpenClaw Autopilot adds an autonomous intelligence layer to your Wazuh SIEM using OpenClaw agents connected via MCP. It auto-triages alerts, correlates incidents, and generates response plans — with mandatory two-tier human approval before execution.
What you get
7 specialized SOC agents
Triage → Correlation → Investigation → Planning → Policy guard → Human approval → Responder + Reporting.
Two-tier approvals
Every response action is gated. Autopilot proposes, humans approve, then execution happens.
Security-first networking
Localhost bindings + VPN-only MCP access — designed so nothing needs to be publicly exposed.
Operational visibility
Prometheus metrics for MTTD, MTTR, triage latency, approvals, executions and policy denies.
Quick demo flow
From alert storm → to a clean, human-approved response.
- Alert comes in from Wazuh
- Agents extract entities + correlate into a case
- Planner creates a response plan + risk notes
- Policy guard checks allow-list / deny rules
- Humans approve → responder executes via Wazuh Active Response
Explore use cases
Architecture
A clean separation between SIEM data, tool access, agent reasoning, and execution — with approvals in the middle.
WAZUH MANAGER ──▶ MCP SERVER ◀──▶ OPENCLAW GATEWAY ──▶ 7 SOC AGENTS
│ │ │
Alerts Wazuh API AI orchestration
│ │ │
▼ ▼ ▼
AUTOPILOT RUNTIME SERVICE
cases • evidence packs • response plans • metrics • slack
Key metrics
Expose SOC KPIs and performance indicators at /metrics.
Verify installation
FAQ (for rich results)
Does Autopilot execute actions automatically?
It generates plans automatically, but response actions require mandatory human approval before execution.
Can I run it air-gapped?
Yes. Air‑gapped deployments are supported with a local LLM provider like Ollama.
Do I have to expose anything to the public internet?
No. Components are designed to bind to localhost and/or VPN-only access (e.g., Tailscale).
What SIEM does it support?
It’s built for Wazuh SIEM (Wazuh Manager 4.8.0+).