Profile
Back to NewsBack
GitHub Trending 5 min
Reader Mode
fabriziosalmi/wildbox: An open-source security platform for the community. Unified SIEM, SOAR, WAF, and more in a single, self-hosted solution.

fabriziosalmi/wildbox: An open-source security platform for the community. Unified SIEM, SOAR, WAF, and more in a single, self-hosted solution.

4 hours ago

Wildbox

Wildbox

Self-hosted, open-source security operations platform.

License: MIT</a> Test Suite</a> Integration Tests</a> Release</a>

Documentation · Quick start · Changelog · Security policy

Wildbox runs threat intelligence, cloud posture checks, vulnerability tracking, security tooling and automated response as a set of services behind one authenticating gateway, on your own hardware, with your data staying there.

Wildbox is pre-1.0. Interfaces can change between minor releases; read UPGRADING.md before moving to a new version.

!Wildbox dashboard

Capabilities

| Area | What it does | Service | | :--- | :--- | :--- | | Gateway | Single HTTPS entry point: authentication, per-IP and per-team rate limiting, routing | open-security-gateway | | Identity | Users, teams, roles, API keys with scopes, JWT sessions with server-side revocation | open-security-identity | | Security tools | 52 tools behind one API (DNS, TLS, email security, headers, ports, and more) | open-security-tools | | Threat intelligence | Indicator collection from 7 public feeds (abuse.ch, PhishTank, AbuseIPDB and others) and lookup | open-security-data | | Cloud posture | 22 checks against live AWS accounts; GCP and Azure are not supported, and scans of them are refused | open-security-cspm | | Vulnerabilities | Asset inventory, findings, risk-based prioritization, remediation tracking | open-security-guardian | | Response | YAML playbooks executed as background jobs | open-security-responder | | Endpoint telemetry | osquery-based telemetry from hosts running the sensor | open-security-sensor | | Analysis | Threat-enrichment reports generated with Anthropic Claude | open-security-agents | | Interface | Web dashboard | open-security-dashboard |

Architecture

Every request from outside enters through the gateway. Backend services listen on 127.0.0.1 only, PostgreSQL and Redis publish no port at all, and each backend rejects requests that do not carry the gateway's proof-of-origin secret.

flowchart LR
    client[Browser / API client / sensor] -->|HTTPS 443| gateway[Gateway<br/>OpenResty]
    gateway --> identity[Identity]
    gateway --> tools[Tools]
    gateway --> data[Data]
    gateway --> cspm[CSPM]
    gateway --> guardian[Guardian]
    gateway --> responder[Responder]
    gateway --> agents[Agents]
    gateway --> dashboard[Dashboard]
    identity --> pg[(PostgreSQL 15)]
    data --> pg
    guardian --> pg
    responder --> pg
    identity --> redis[(Redis 7)]
    tools --> redis
    cspm --> redis
    responder --> redis
    agents --> redis
    agents --> claude[Anthropic API]
    cspm --> clouds[AWS APIs]
    data --> feeds[Public threat feeds]

Quick start

Requirements

  • Docker Engine 24 or later with the Compose plugin (docker compose)
  • 8 GB of RAM (16 GB recommended), 20 GB of free disk
  • Linux, macOS, or Windows with WSL 2

Install and start

git clone https://github.com/fabriziosalmi/wildbox.git
cd wildbox

make generate-secrets # writes .env with random values for every secret (mode 0600)

edit INITIAL_ADMIN_EMAIL in .env: it is the login of the first administrator

make validate-secrets # refuses placeholder values

docker compose up -d --wait # builds and starts the stack; the first build takes several minutes

This is the configuration the integration suite starts and tests on every change.

Verify

The gateway serves HTTPS with a certificate generated at first start. Trust it explicitly rather than disabling verification:

curl --cacert open-security-gateway/ssl/wildbox.crt https://localhost/health

Log in with the initial administrator. The email is the one you set in .env; the password was generated there by make generate-secrets:

ADMIN_EMAIL=$(sed -n 's/^INITIAL_ADMIN_EMAIL=//p' .env)
ADMIN_PASSWORD=$(sed -n 's/^INITIAL_ADMIN_PASSWORD=//p' .env)

TOKEN=$(curl -s --cacert open-security-gateway/ssl/wildbox.crt \ --data-urlencode "username=$ADMIN_EMAIL" \ --data-urlencode "password=$ADMIN_PASSWORD" \ https://localhost/auth/jwt/login | python3 -c 'import json,sys; print(json.load(sys.stdin)["access_token"])')

curl --cacert open-security-gateway/ssl/wildbox.crt \ -H "Authorization: Bearer $TOKEN" https://localhost/api/v1/tools

Open the dashboard at https://localhost and sign in with the same account. Change the initial password after the first login.

Optional services

| Service | Start with | | :--- | :--- | | Workflow automation (n8n) | docker compose --profile automations up -d | | Prometheus | docker compose --profile monitoring up -d | | Scheduled backups | docker compose --profile backup up -d |

Operations

| Task | Command | | :--- | :--- | | Service status | docker compose ps | | Logs | docker compose logs -f | | Full health check | make health | | Production overlay | make start-prod (adds docker-compose.prod.yml) | | Back up PostgreSQL | make backup | | Rehearse a restore | make restore-drill | | List rotatable secrets | make rotate-secrets | | Stop | docker compose down |

Ports, service names and bindings are listed in one place: ports reference. Production guidance is in the deployment guide.

Security

  • Report vulnerabilities privately as described in SECURITY.md.
  • The current state of known security issues, including what is still open, is
published on the security status page.
  • Every Python service ships a hash-pinned lockfile compiled from
requirements.in; CI blocks pull requests that introduce a critical advisory, and a daily job reports any found on main.

Development

make lock             # recompile every service's hash-pinned requirements.txt
make lock-security    # move only packages with known advisories
make test             # identity and guardian test suites, inside the running containers

Unit tests run per service; see .github/workflows/test.yml for the exact commands CI uses. Contribution guidelines: CONTRIBUTING.md. Engineering documents (architecture decisions, testing strategy, service lifecycle) are indexed on the contributor docs page.

Documentation

| Topic | Link | | :--- | :--- | | Documentation portal | wildbox.io/docs.html | | Quick start (detailed) | guides/quickstart | | Credentials | guides/credentials | | Authentication and sessions | guides/authentication | | API reference | wildbox.io/api | | Upgrading between versions | UPGRADING.md | | Troubleshooting | TROUBLESHOOTING.md |

Support

License

MIT

Chat with me