Skip to content

Dylan-Aung/SOC-Automation-Project

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

23 Commits
 
 
 
 

Repository files navigation

SOC Automation Project

High-Level Workflow Diagram

Lab Objectives

In modern enterprise environments, security teams must react quickly to threats while handling large volumes of alerts. Manual investigation and response can cause delays that attackers exploit.

This lab demonstrates a fully automated SOC workflow where endpoint security events from a Windows 10 system are collected by Wazuh, processed by Shuffle SOAR, enriched with OSINT threat intelligence, documented in TheHive, and delivered to a SOC analyst via email for action.

The workflow also supports bi-directional response, allowing analysts to trigger automated actions that are executed back on the affected endpoint through Wazuh.


Technical Prerequisites

Name Links
Virtual Box https://www.virtualbox.org/
Window 11 https://www.microsoft.com/en-us/software-download/windows11
Sysmon https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
Sysmon Config https://github.com/olafhartong/sysmon-modular
Wazuh https://duo.com/docs/checksums#duo-windows-logon
TheHive https://docs.strangebee.com/thehive/installation/installation-guide-linux-standalone-server/
Shuffle https://shuffler.io/

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published