Wardex
A Rust-built XDR and SIEM platform for private-cloud deployment. Wardex brings endpoint, network, and cloud telemetry into a shared correlation and response model.
Cross-layer detection with controlled deployment
Wardex treats endpoint, network, and cloud observations as parts of one security graph rather than separate products. Detection rules and model manifests are versioned, and response actions pass through an explicit approval and safety gate.
The system is designed for organisations that need threat detection and fleet operations without exporting raw operational telemetry to a vendor cloud.
- 01Endpoint, network, and cloud collection layers
- 02Streaming correlation graph for entity-linked events
- 03Rule and model-based detectors with provenance
- 04Response orchestration with approval controls and receipts
Federated intrusion detection under operational constraints
The associated research examines federated intrusion detection for constrained IoT environments, including compressed updates, drift, heterogeneous participants, and the cost of participation on weaker devices.
The project connects model behaviour to operational evidence: a detection should be traceable to its feature specification, model version, drift state, and response decision.
Evidence boundary
Wardex is a functioning security platform and an active research vehicle. The project does not treat a model score alone as proof of security effectiveness; evaluation claims remain tied to the stated experiments and deployment conditions.