Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
pub:soc [26.11.2024 09:05] – created Predrag Tasevskipub:soc [14.07.2026 10:05] (current) – full new scope and as it is now Predrag Tasevski
Line 1: Line 1:
-====== Unicis SOC Plan ======+====== Unicis SOC  ======
  
-Comprehensive breakdown of features and integrations for UNICIS SOC stack that includes Wazuh, TheHive, Zabbix, MISP, Cortex, and Shuffle SOAR.+<WRAP center round info> 
 +The Unicis SOC is live in production — not a planned initiative. This page documents the security operations stack as currently deployed. 
 +</WRAP>
  
-Integrated Features +===== Monitoring & Detection =====
-1. Centralised Incident Management +
-Wazuh + TheHive: +
-Automate alert ingestion from Wazuh into TheHive to create structured cases. +
-Analysts triage Wazuh alerts in TheHive and enrich them with observables from threat intelligence (via Cortex and MISP). +
-Zabbix + TheHive: +
-Send Zabbix performance or anomaly alerts to TheHive for further analysis. +
-Automatically create cases in TheHive when Zabbix detects critical infrastructure issues that may indicate security concerns. +
-TheHive + Shuffle SOAR: +
-Use Shuffle to automate TheHive workflows, such as escalating alerts to incidents, assigning tasks, or notifying teams.+
  
-2. Automated Threat Intelligence Integration +  * **Wazuh** – Live, full production deployment providing
-Wazuh + MISP+    * **Asset visibility** across all servers and VPS instances 
-Export Wazuh-detected IoCs (e.g.IPsdomains, hashes) to MISP for community sharing. +    * **Threat intelligence** — vulnerability detectionthreat hunting, and MITRE ATT&CK-mapped detections 
-Use MISP threat feeds in Wazuh for correlation with logs and real-time alerts. +    * **Security alerts** across the fleet 
-MISP + TheHive: +    * **Endpoint security** — configuration assessmentmalware detection, and file integrity monitoring (FIM) 
-Automatically correlate IoCs from MISP with incidents in TheHive. +    * **IT Hygiene** monitoring 
-Enrich TheHive cases with detailed threat actor profilestactics, and related indicators from MISP. +    * **GDPR** compliance monitoring 
-MISP Cortex: +    * **Docker/container monitoring** 
-Leverage Cortex analyzers to validate and enrich MISP IoCs (e.g.domain reputationIP geolocation). +  * **Prometheus Grafana** – Infrastructure monitoring and alerting across all servers (resource usageuptimeperformance anomalies). 
-Cortex results can be fed back into MISP to keep threat intelligence updated. +  * **CrowdSec** – Security monitoring and threat detection, integrated with Grafana; blocks and alerts on suspicious activity across all servers.
-Shuffle + MISP: +
-Automate the ingestion of new threat feeds into MISP and push updates to Wazuh. +
-Trigger Shuffle workflows for MISP when new IoCs are detected, such as adding alerts to Wazuh or sharing them with other organisations.+
  
-3. Proactive Alert Management +===== Access Control =====
-Wazuh + Zabbix: +
-Correlate Wazuh alerts with Zabbix metrics to identify suspicious activities with infrastructure context. +
-Zabbix + Shuffle SOAR: +
-Automate responses to Zabbix alerts, such as restarting failing services or notifying teams about resource exhaustion. +
-TheHive + Cortex: +
-When alerts in TheHive contain observables (IPs, domains, hashes), Cortex analyzers automatically enrich them with actionable intelligence. +
-TheHive + Shuffle SOAR: +
-Use Shuffle to assign tasks in TheHive, send notifications to teams, and escalate alerts based on severity or case type.+
  
-4. Enhanced Visualisations +  * **SSO** enforced across all internal tools and platforms
-Zabbix Dashboards: +  * **Software firewall** enabled on all servers.
-Combine security alerts from Wazuh with performance metrics from Zabbix into unified dashboards. +
-TheHive Analytics: +
-Analyse incident trends and response times, enhanced by enriched threat data from MISP and Cortex+
-Shuffle Dashboards: +
-Use Shuffle to create centralised dashboards displaying SOC-wide metrics: alert counts, case statuses, response SLAs, and resolved incidents.+
  
-5. Automated Playbooks +===== Status Page =====
-Shuffle SOAR: +
-Automate multi-step responses, such as: +
-Triggering Cortex enrichment for new TheHive observables. +
-Updating MISP with new IoCs detected by Wazuh or validated by Cortex. +
-Quarantining affected endpoints using Wazuh triggers. +
-TheHive Playbooks: +
-Guide analysts through consistent incident response workflows: +
-Example: Phishing case playbook → Analyze email headers in Cortex → Cross-check domains in MISP → Update case findings in TheHive.+
  
-6Improved Threat Detection +  * **status.unicis.tech** – Static status page built on [[https://cstate.dashbase.io/|cState]]updated automatically via MonitorBot.
-Wazuh + Cortex: +
-Automatically enrich Wazuh alerts using Cortex analyzers (e.g., VirusTotal for file hashes, AbuseIPDB for IPs). +
-Highlight false positives or flag high-risk threats based on enrichment data. +
-MISP + Shuffle SOAR: +
-Detect changes in MISP IoCs and trigger Shuffle workflows to alert Wazuh or update TheHive cases. +
-Zabbix + MISP: +
-Correlate Zabbix anomaly alerts with known threat patterns in MISPenabling proactive detection of infrastructure-based attacks.+
  
-Standalone Features +===== Automation & Integration =====
-Wazuh +
-Intrusion detection through log monitoring, anomaly detection, and file integrity checks. +
-Host-based monitoring with custom rule sets for advanced threat detection. +
-Compliance audits for standards like PCI-DSS, HIPAA, and GDPR.+
  
-TheHive +  * All monitoring and security tooling above is connected via an MCP (Model Context Protocol) serverenabling centralized querying, automationand AI-assisted operations across the stack.
-Incident management with case trackingobservablesand collaboration tools. +
-Playbook automation for standardised incident handling. +
-Trend analysis for understanding recurring threats and response efficiency.+
  
-Zabbix +===== ComplianceIncidentAsset & Training Tooling =====
-Resource monitoring across serversapplicationsnetworks, and databases. +
-Trend analysis for resource utilisation and performance anomalies. +
-Custom alerting for proactive response to potential issues.+
  
-MISP +^ Function ^ Current tool ^ Status ^ 
-Centralised threat intelligence management and sharing platform. +| Compliance checks | Unicis Platform | Live — used for MVSP/audit checklistsGDPR, and risk management | 
-Import/export of IoCs in formats like STIXJSON, and CSV. +| Incident management | Unicis Platform | Planned — will move to Unicis Platform once the Incident Management module is deployed | 
-Advanced IOC correlation and search for identifying related campaigns.+| Asset management | Unicis Platform | Planned — will move to Unicis Platform once deployed in an upcoming release | 
 +| Training / awareness (internal) | Unicis Platform — Interactive Awareness Training Program module | Live — internal security awareness training | 
 +| Training (remote/external, EU projects) | Moodle | Live — see [[pub:operations:tech_stack_applications#moodle|Tech Stack]] |
  
-Cortex +{{tag>soc security wazuh grafana prometheus crowdsec firewall sso status-page mcp compliance}}
-Observable enrichment using powerful analyzers like VirusTotal, PassiveTotal, and WHOIS lookup. +
-Automation of threat intelligence workflows with integration to other tools like MISP and TheHive. +
-Supports hundreds of analyzers for advanced threat data insights. +
- +
-Shuffle SOAR +
-Orchestrates and automates workflows across all integrated tools. +
-Provides a centralised automation hub to connect Wazuh, Zabbix, MISP, TheHive, and Cortex. +
-Simplifies repetitive tasks like alert forwarding, case creation, and threat enrichment. +
- +