Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| pub:soc [26.11.2024 09:05] – created Predrag Tasevski | pub:soc [14.07.2026 10:05] (current) – full new scope and as it is now Predrag Tasevski | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Unicis SOC Plan ====== | + | ====== Unicis SOC ====== |
| - | Comprehensive breakdown of features and integrations for UNICIS | + | <WRAP center round info> |
| + | The Unicis | ||
| + | </ | ||
| - | Integrated Features | + | ===== Monitoring & Detection ===== |
| - | 1. Centralised Incident Management | + | |
| - | Wazuh + TheHive: | + | |
| - | Automate alert ingestion from Wazuh into TheHive to create structured cases. | + | |
| - | Analysts triage Wazuh alerts in TheHive and enrich them with observables from threat intelligence (via Cortex and MISP). | + | |
| - | Zabbix + TheHive: | + | |
| - | Send Zabbix performance or anomaly alerts to TheHive for further analysis. | + | |
| - | Automatically create cases in TheHive when Zabbix detects critical infrastructure issues that may indicate security concerns. | + | |
| - | TheHive + Shuffle SOAR: | + | |
| - | Use Shuffle to automate TheHive workflows, such as escalating alerts to incidents, assigning tasks, or notifying teams. | + | |
| - | 2. Automated Threat Intelligence Integration | + | * **Wazuh** – Live, full production deployment providing: |
| - | Wazuh + MISP: | + | * **Asset visibility** across all servers and VPS instances |
| - | Export Wazuh-detected IoCs (e.g., IPs, domains, hashes) to MISP for community sharing. | + | * **Threat intelligence** — vulnerability detection, threat hunting, and MITRE ATT&CK-mapped detections |
| - | Use MISP threat feeds in Wazuh for correlation with logs and real-time alerts. | + | * **Security |
| - | MISP + TheHive: | + | * **Endpoint security** — configuration assessment, malware detection, and file integrity monitoring (FIM) |
| - | Automatically correlate IoCs from MISP with incidents in TheHive. | + | * **IT Hygiene** monitoring |
| - | Enrich TheHive cases with detailed threat actor profiles, tactics, and related indicators from MISP. | + | * **GDPR** compliance monitoring |
| - | MISP + Cortex: | + | * **Docker/ |
| - | Leverage Cortex analyzers to validate | + | * **Prometheus |
| - | Cortex results can be fed back into MISP to keep threat | + | * **CrowdSec** – Security monitoring and threat |
| - | Shuffle + MISP: | + | |
| - | Automate the ingestion of new threat feeds into MISP and push updates to Wazuh. | + | |
| - | Trigger Shuffle workflows for MISP when new IoCs are detected, such as adding | + | |
| - | 3. Proactive Alert Management | + | ===== Access Control ===== |
| - | Wazuh + Zabbix: | + | |
| - | Correlate Wazuh alerts with Zabbix metrics to identify suspicious activities with infrastructure context. | + | |
| - | Zabbix + Shuffle SOAR: | + | |
| - | Automate responses to Zabbix alerts, such as restarting failing services or notifying teams about resource exhaustion. | + | |
| - | TheHive + Cortex: | + | |
| - | When alerts in TheHive contain observables (IPs, domains, hashes), Cortex analyzers automatically enrich them with actionable intelligence. | + | |
| - | TheHive + Shuffle SOAR: | + | |
| - | Use Shuffle to assign tasks in TheHive, send notifications to teams, and escalate alerts based on severity or case type. | + | |
| - | 4. Enhanced Visualisations | + | * **SSO** enforced across all internal tools and platforms. |
| - | Zabbix Dashboards: | + | * **Software firewall** enabled on all servers. |
| - | Combine security alerts from Wazuh with performance metrics from Zabbix into unified dashboards. | + | |
| - | TheHive Analytics: | + | |
| - | Analyse incident trends | + | |
| - | Shuffle Dashboards: | + | |
| - | Use Shuffle to create centralised dashboards displaying SOC-wide metrics: alert counts, case statuses, response SLAs, and resolved incidents. | + | |
| - | 5. Automated Playbooks | + | ===== Status Page ===== |
| - | Shuffle SOAR: | + | |
| - | Automate multi-step responses, such as: | + | |
| - | Triggering Cortex enrichment for new TheHive observables. | + | |
| - | Updating MISP with new IoCs detected by Wazuh or validated by Cortex. | + | |
| - | Quarantining affected endpoints using Wazuh triggers. | + | |
| - | TheHive Playbooks: | + | |
| - | Guide analysts through consistent incident response workflows: | + | |
| - | Example: Phishing case playbook → Analyze email headers in Cortex → Cross-check domains in MISP → Update case findings in TheHive. | + | |
| - | 6. Improved Threat Detection | + | * **status.unicis.tech** – Static status page built on [[https://cstate.dashbase.io/ |
| - | Wazuh + Cortex: | + | |
| - | Automatically enrich Wazuh alerts using Cortex analyzers (e.g., VirusTotal for file hashes, AbuseIPDB for IPs). | + | |
| - | Highlight false positives or flag high-risk threats based on enrichment data. | + | |
| - | MISP + Shuffle SOAR: | + | |
| - | Detect changes in MISP IoCs and trigger Shuffle workflows to alert Wazuh or update TheHive cases. | + | |
| - | Zabbix + MISP: | + | |
| - | Correlate Zabbix anomaly alerts with known threat patterns in MISP, enabling proactive detection of infrastructure-based attacks. | + | |
| - | Standalone Features | + | ===== Automation & Integration ===== |
| - | Wazuh | + | |
| - | Intrusion detection through log monitoring, anomaly detection, and file integrity checks. | + | |
| - | Host-based monitoring with custom rule sets for advanced threat detection. | + | |
| - | Compliance audits for standards like PCI-DSS, HIPAA, and GDPR. | + | |
| - | TheHive | + | * All monitoring and security tooling above is connected via an MCP (Model Context Protocol) server, enabling centralized querying, automation, and AI-assisted operations across the stack. |
| - | Incident management with case tracking, observables, and collaboration tools. | + | |
| - | Playbook | + | |
| - | Trend analysis for understanding recurring threats | + | |
| - | Zabbix | + | ===== Compliance, Incident, Asset & Training Tooling ===== |
| - | Resource monitoring across servers, applications, networks, and databases. | + | |
| - | Trend analysis for resource utilisation and performance anomalies. | + | |
| - | Custom alerting for proactive response to potential issues. | + | |
| - | MISP | + | ^ Function ^ Current tool ^ Status ^ |
| - | Centralised threat intelligence management and sharing platform. | + | | Compliance checks | Unicis Platform | Live — used for MVSP/audit checklists, GDPR, and risk management | |
| - | Import/export of IoCs in formats like STIX, JSON, and CSV. | + | | Incident management | Unicis Platform | Planned — will move to Unicis Platform once the Incident Management module is deployed | |
| - | Advanced IOC correlation and search for identifying related campaigns. | + | | Asset management | Unicis Platform | Planned — will move to Unicis Platform once deployed in an upcoming release | |
| + | | Training / awareness (internal) | Unicis Platform — Interactive Awareness Training Program module | Live — internal security awareness training | | ||
| + | | Training (remote/ | ||
| - | Cortex | + | {{tag> |
| - | Observable enrichment using powerful analyzers like VirusTotal, PassiveTotal, | + | |
| - | Automation of threat intelligence workflows with integration to other tools like MISP and TheHive. | + | |
| - | Supports hundreds of analyzers for advanced threat data insights. | + | |
| - | + | ||
| - | Shuffle SOAR | + | |
| - | Orchestrates and automates workflows across all integrated tools. | + | |
| - | Provides a centralised automation hub to connect Wazuh, Zabbix, MISP, TheHive, and Cortex. | + | |
| - | Simplifies repetitive tasks like alert forwarding, case creation, and threat enrichment. | + | |
| - | + | ||