SIEM Correlation Engine: Sliding-Window Threshold Detection
Interactive SIEM correlation-rule simulator: log events stream from multiple hosts into a central engine that fires an alert only when enough matching events land inside a sliding time window. Tune the window, threshold and noise rate and watch true and false positives play out live.
Security Information and Event Management platforms don't detect attacks by magic — they run correlation rules over a firehose of log events. This simulator renders the most common rule type, a sliding-window count threshold, in real 3D: six hosts stream ordinary background noise and occasional brute-force bursts toward a central correlation engine, and an alert only fires once enough matching events land inside the current time window for the same host. Tune the window length, the event threshold, and the background noise rate to see the true-positive/false-positive tradeoff every SOC analyst tunes in production, then inject a brute-force attack and watch the mean-time-to-detect play out live.
Watch log events stream from six hosts into a central SIEM correlation engine that only raises an alert once enough matching events land inside a sliding time window, and tune the window, threshold and noise rate to see the true-positive/false-positive tradeoff a real SOC tunes in production.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install