Academic project · 02 / 06 · security operations

Wardex

A Rust-built XDR and SIEM platform for private-cloud deployment. Wardex brings endpoint, network, and cloud telemetry into a shared correlation and response model.

StatusRelease · active
Version1.0.30
StackRust · XDR · ONNX
PaperTechRxiv · 2025
01 · Overview

Cross-layer detection with controlled deployment

Wardex treats endpoint, network, and cloud observations as parts of one security graph rather than separate products. Detection rules and model manifests are versioned, and response actions pass through an explicit approval and safety gate.

The system is designed for organisations that need threat detection and fleet operations without exporting raw operational telemetry to a vendor cloud.

  • 01Endpoint, network, and cloud collection layers
  • 02Streaming correlation graph for entity-linked events
  • 03Rule and model-based detectors with provenance
  • 04Response orchestration with approval controls and receipts
02 · Research

Federated intrusion detection under operational constraints

The associated research examines federated intrusion detection for constrained IoT environments, including compressed updates, drift, heterogeneous participants, and the cost of participation on weaker devices.

The project connects model behaviour to operational evidence: a detection should be traceable to its feature specification, model version, drift state, and response decision.

Evidence boundary

Wardex is a functioning security platform and an active research vehicle. The project does not treat a model score alone as proof of security effectiveness; evaluation claims remain tied to the stated experiments and deployment conditions.

Related preprint: Federated Intrusion Detection for Resource-Constrained IoT Environments.
03 · Related

Continue through the research portfolio