SOAR and Incident Response Automation: Playbooks in Action
1. Introduction SOAR incident response automation is the natural evolution of any security operations center that has outgrown email alerts and Excel spreadsheets. When a SOC matures, the alert volume grows faster than the team that must analyze it, which is where automation stops being a luxury and becomes an operational necessity. This article explains what lies behind SOAR incident response automation, with real examples you can adapt to your own environment. I will assume you already know what a SIEM is and how a basic SOC works: if you need to refresh that foundation, the end of this article …
SIEM Implementation with Wazuh: From Deployment to Detection
1. Introduction SIEM implementation with Wazuh has become the natural entry point for any team that wants to move from scattered monitoring to a functional Security Operations Center (SOC). Wazuh combines in a single open source platform event correlation, host-based intrusion detection (HIDS), file integrity monitoring and active response, all with zero license cost and a reasonable learning curve. In this article we perform a complete lab of SIEM implementation with Wazuh on an Ubuntu Server 22.04 environment, starting from scratch: we deploy the full stack with Docker Compose, integrate Windows and Linux agents, define custom rules and automate the …
Master SOC on BOX: Implementation of a SIEM/SOC service – (Part 2).
Implementation and launch of a SIEM/SOC Service. …
Master SOC on BOX: Implementation of a SIEM/SOC service – (Part 1).
Implementation and launch of a SIEM/SOC Service. …

