Full technical walkthrough: Public SSH Honeypot → On-Prem Wazuh SIEM

A 30-minute walkthrough of my public SSH honeypot lab, showing how Cowrie on a VPS forwards real attacker activity into an on-prem Wazuh SIEM through a segmented network. I cover the architecture, logging pipeline, custom rules, dashboards, and examples of captured SSH activity including login attempts, commands, and file uploads.