Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| pub:soc [26.11.2024 16:00] – Predrag Tasevski | pub:soc [14.07.2026 10:05] (current) – full new scope and as it is now Predrag Tasevski | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Unicis SOC Plan ====== | + | ====== Unicis SOC ====== |
| <WRAP center round info> | <WRAP center round info> | ||
| - | Comprehensive breakdown of features and integrations for UNICIS | + | The Unicis |
| </ | </ | ||
| + | ===== Monitoring & Detection ===== | ||
| - | ===== Integrated Features ===== | + | * **Wazuh** – Live, full production deployment providing: |
| + | * **Asset visibility** across all servers and VPS instances | ||
| + | * **Threat intelligence** — vulnerability detection, threat hunting, and MITRE ATT& | ||
| + | * **Security alerts** across the fleet | ||
| + | * **Endpoint security** — configuration assessment, malware detection, and file integrity monitoring (FIM) | ||
| + | * **IT Hygiene** monitoring | ||
| + | * **GDPR** compliance monitoring | ||
| + | * **Docker/ | ||
| + | * **Prometheus + Grafana** – Infrastructure monitoring and alerting across all servers (resource usage, uptime, performance anomalies). | ||
| + | * **CrowdSec** – Security monitoring and threat detection, integrated with Grafana; blocks and alerts on suspicious activity across all servers. | ||
| - | ==== 1. Centralised Incident Management | + | ===== Access Control ===== |
| - | * Wazuh + TheHive: | + | * **SSO** enforced across all internal tools and platforms. |
| - | * Automate alert ingestion from Wazuh into TheHive to create structured cases. | + | * **Software firewall** enabled on all servers. |
| - | * Analysts triage Wazuh alerts in TheHive | + | |
| - | | + | |
| - | * Send Zabbix performance or anomaly alerts to TheHive for further analysis. | + | |
| - | * Automatically create cases in TheHive when Zabbix detects critical infrastructure issues that may indicate security concerns. | + | |
| - | * TheHive + Shuffle SOAR: | + | |
| - | * Use Shuffle to automate TheHive workflows, such as escalating alerts to incidents, assigning tasks, or notifying teams. | + | |
| - | ==== 2. Automated Threat Intelligence Integration | + | ===== Status Page ===== |
| - | * Wazuh + MISP: | + | * **status.unicis.tech** – Static status page built on [[https://cstate.dashbase.io/ |
| - | | + | |
| - | | + | |
| - | * MISP + TheHive: | + | |
| - | * Automatically correlate IoCs from MISP with incidents in TheHive. | + | |
| - | | + | |
| - | | + | |
| - | * Leverage Cortex analyzers to validate and enrich MISP IoCs (e.g., domain reputation, IP geolocation). | + | |
| - | * Cortex results can be fed back into MISP to keep threat intelligence | + | |
| - | * Shuffle + MISP: | + | |
| - | * Automate the ingestion of new threat feeds into MISP and push updates to Wazuh. | + | |
| - | * Trigger Shuffle workflows for MISP when new IoCs are detected, such as adding alerts to Wazuh or sharing them with other organisations. | + | |
| - | ==== 3. Proactive Alert Management | + | ===== Automation & Integration ===== |
| - | * Wazuh + Zabbix: | + | * All monitoring and security tooling above is connected via an MCP (Model Context Protocol) server, enabling centralized querying, automation, and AI-assisted operations across the stack. |
| - | * Correlate Wazuh alerts with Zabbix metrics to identify suspicious activities with infrastructure context. | + | |
| - | * Zabbix + Shuffle SOAR: | + | |
| - | * Automate responses to Zabbix alerts, such as restarting failing services or notifying teams about resource exhaustion. | + | |
| - | * TheHive + Cortex: | + | |
| - | * When alerts in TheHive contain observables | + | |
| - | * TheHive + Shuffle SOAR: | + | |
| - | * Use Shuffle to assign tasks in TheHive, send notifications to teams, and escalate alerts based on severity or case type. | + | |
| - | ==== 4. Enhanced Visualisations | + | ===== Compliance, Incident, Asset & Training Tooling ===== |
| - | * Zabbix Dashboards: | + | ^ Function ^ Current tool ^ Status ^ |
| - | * Combine security alerts from Wazuh with performance metrics from Zabbix into unified dashboards. | + | | Compliance checks | Unicis Platform | Live — used for MVSP/audit checklists, GDPR, and risk management | |
| - | * TheHive Analytics: | + | | Incident management | Unicis Platform | Planned — will move to Unicis Platform once the Incident Management module is deployed | |
| - | * Analyse incident trends and response times, enhanced by enriched threat data from MISP and Cortex. | + | | Asset management | Unicis Platform | Planned — will move to Unicis Platform once deployed in an upcoming release | |
| - | * Shuffle Dashboards: | + | | Training / awareness (internal) | Unicis Platform — Interactive Awareness Training Program module | Live — internal security awareness training | |
| - | * Use Shuffle | + | | Training (remote/ |
| - | ==== 5. Automated Playbooks ==== | + | {{tag> |
| - | + | ||
| - | * Shuffle SOAR: | + | |
| - | * Automate multi-step responses, such as: | + | |
| - | * Triggering Cortex enrichment for new TheHive observables. | + | |
| - | * Updating MISP with new IoCs detected by Wazuh or validated by Cortex. | + | |
| - | * Quarantining affected endpoints using Wazuh triggers. | + | |
| - | * TheHive Playbooks: | + | |
| - | * Guide analysts through consistent incident response workflows: | + | |
| - | * Example: Phishing case playbook → Analyze email headers in Cortex → Cross-check domains in MISP → Update case findings in TheHive. | + | |
| - | + | ||
| - | ==== 6. Improved Threat Detection ==== | + | |
| - | + | ||
| - | * Wazuh + Cortex: | + | |
| - | * Automatically enrich Wazuh alerts using Cortex analyzers (e.g., VirusTotal for file hashes, AbuseIPDB for IPs). | + | |
| - | * Highlight false positives or flag high-risk threats based on enrichment data. | + | |
| - | * MISP + Shuffle SOAR: | + | |
| - | * Detect changes in MISP IoCs and trigger Shuffle workflows to alert Wazuh or update TheHive cases. | + | |
| - | * Zabbix + MISP: | + | |
| - | * Correlate Zabbix anomaly alerts with known threat patterns in MISP, enabling proactive detection of infrastructure-based attacks. | + | |
| - | + | ||
| - | ===== Standalone Features ===== | + | |
| - | + | ||
| - | ==== Wazuh ==== | + | |
| - | + | ||
| - | * Intrusion detection through log monitoring, anomaly detection, and file integrity checks. | + | |
| - | * Host-based monitoring with custom rule sets for advanced threat detection. | + | |
| - | * Compliance audits for standards like PCI-DSS, HIPAA, and GDPR. | + | |
| - | + | ||
| - | ==== TheHive ==== | + | |
| - | + | ||
| - | * Incident management with case tracking, observables, | + | |
| - | * Playbook automation for standardised incident handling. | + | |
| - | * Trend analysis for understanding recurring threats and response efficiency. | + | |
| - | + | ||
| - | ==== Zabbix ==== | + | |
| - | + | ||
| - | * Resource monitoring across servers, applications, | + | |
| - | * Trend analysis for resource utilisation and performance anomalies. | + | |
| - | * Custom alerting for proactive response to potential issues. | + | |
| - | + | ||
| - | ==== MISP ==== | + | |
| - | + | ||
| - | * Centralised threat intelligence management and sharing platform. | + | |
| - | * Import/ | + | |
| - | * Advanced IOC correlation and search for identifying related campaigns. | + | |
| - | + | ||
| - | ==== Cortex ==== | + | |
| - | + | ||
| - | * Observable enrichment using powerful analyzers like VirusTotal, PassiveTotal, | + | |
| - | * Automation of threat intelligence workflows with integration to other tools like MISP and TheHive. | + | |
| - | * Supports hundreds of analyzers for advanced threat data insights. | + | |
| - | + | ||
| - | ==== Shuffle SOAR ==== | + | |
| - | + | ||
| - | * Orchestrates and automates workflows across all integrated tools. | + | |
| - | * Provides a centralised automation hub to connect Wazuh, Zabbix, MISP, TheHive, and Cortex. | + | |
| - | * Simplifies repetitive tasks like alert forwarding, case creation, and threat enrichment. | + | |
| - | + | ||