You are here: Home » pub » Unicis SOC

Unicis SOC

Unicis SOC

The Unicis SOC is live in production — not a planned initiative. This page documents the security operations stack as currently deployed.

Monitoring & Detection

  • Wazuh – Live, full production deployment providing:
    • Asset visibility across all servers and VPS instances
    • Threat intelligence — vulnerability detection, threat hunting, and MITRE ATT&CK-mapped detections
    • Security alerts across the fleet
    • Endpoint security — configuration assessment, malware detection, and file integrity monitoring (FIM)
    • IT Hygiene monitoring
    • GDPR compliance monitoring
    • Docker/container monitoring
  • Prometheus + Grafana – Infrastructure monitoring and alerting across all servers (resource usage, uptime, performance anomalies).
  • CrowdSec – Security monitoring and threat detection, integrated with Grafana; blocks and alerts on suspicious activity across all servers.

Access Control

  • SSO enforced across all internal tools and platforms.
  • Software firewall enabled on all servers.

Status Page

  • status.unicis.tech – Static status page built on cState, updated automatically via MonitorBot.

Automation & Integration

  • All monitoring and security tooling above is connected via an MCP (Model Context Protocol) server, enabling centralized querying, automation, and AI-assisted operations across the stack.

Compliance, Incident, Asset & Training Tooling

Function Current tool Status
Compliance checks Unicis Platform Live — used for MVSP/audit checklists, GDPR, and risk management
Incident management Unicis Platform Planned — will move to Unicis Platform once the Incident Management module is deployed
Asset management Unicis Platform Planned — will move to Unicis Platform once deployed in an upcoming release
Training / awareness (internal) Unicis Platform — Interactive Awareness Training Program module Live — internal security awareness training
Training (remote/external, EU projects) Moodle Live — see Tech Stack