Unicis SOC
The Unicis SOC is live in production — not a planned initiative. This page documents the security operations stack as currently deployed.
Monitoring & Detection
- Wazuh – Live, full production deployment providing:
- Asset visibility across all servers and VPS instances
- Threat intelligence — vulnerability detection, threat hunting, and MITRE ATT&CK-mapped detections
- Security alerts across the fleet
- Endpoint security — configuration assessment, malware detection, and file integrity monitoring (FIM)
- IT Hygiene monitoring
- GDPR compliance monitoring
- Docker/container monitoring
- Prometheus + Grafana – Infrastructure monitoring and alerting across all servers (resource usage, uptime, performance anomalies).
- CrowdSec – Security monitoring and threat detection, integrated with Grafana; blocks and alerts on suspicious activity across all servers.
Access Control
- SSO enforced across all internal tools and platforms.
- Software firewall enabled on all servers.
Status Page
- status.unicis.tech – Static status page built on cState, updated automatically via MonitorBot.
Automation & Integration
- All monitoring and security tooling above is connected via an MCP (Model Context Protocol) server, enabling centralized querying, automation, and AI-assisted operations across the stack.
Compliance, Incident, Asset & Training Tooling
| Function | Current tool | Status |
|---|---|---|
| Compliance checks | Unicis Platform | Live — used for MVSP/audit checklists, GDPR, and risk management |
| Incident management | Unicis Platform | Planned — will move to Unicis Platform once the Incident Management module is deployed |
| Asset management | Unicis Platform | Planned — will move to Unicis Platform once deployed in an upcoming release |
| Training / awareness (internal) | Unicis Platform — Interactive Awareness Training Program module | Live — internal security awareness training |
| Training (remote/external, EU projects) | Moodle | Live — see Tech Stack |