Skip to content

0xd41AnX8un9/SOC-Automation-Project

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

23 Commits
 
 
 
 

Repository files navigation

SOC Automation Project

High-Level Workflow Diagram

Lab Objectives

In modern enterprise environments, security teams must react quickly to threats while handling large volumes of alerts. Manual investigation and response can cause delays that attackers exploit.

This lab demonstrates a fully automated SOC workflow where endpoint security events from a Windows 10 system are collected by Wazuh, processed by Shuffle SOAR, enriched with OSINT threat intelligence, documented in TheHive, and delivered to a SOC analyst via email for action.

The workflow also supports bi-directional response, allowing analysts to trigger automated actions that are executed back on the affected endpoint through Wazuh.


Technical Prerequisites

Name Links
Virtual Box https://www.virtualbox.org/
Window 11 https://www.microsoft.com/en-us/software-download/windows11
Sysmon https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
Sysmon Config https://github.com/olafhartong/sysmon-modular
Wazuh https://duo.com/docs/checksums#duo-windows-logon
TheHive https://docs.strangebee.com/thehive/installation/installation-guide-linux-standalone-server/
Shuffle https://shuffler.io/

About

This lab demonstrates a fully automated SOC workflow where endpoint security events from a Windows 10 system are collected by Wazuh, processed by Shuffle SOAR, enriched with OSINT threat intelligence, documented in TheHive, and delivered to a SOC analyst via email for action.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors