F.O.S.S.O.C. || Free & open-source Security Operations Centre
GithubTeam
  • Overview
    • Need for this project
    • Aim of this project
    • Network Architecture
    • System Specifications
  • Wazuh Manager
    • Setup
    • Log Behaviour
      • Creating logs for every event
      • Adding custom Wazuh Rules
        • CLI method
        • GUI method
    • Rules
      • Mimikatz Rule
    • Integration
      • With Shuffle
  • Wazuh Agent (Windows)
    • Setup
  • Sysmon
    • Setup
  • TheHive
    • Setup
    • Integrating with Shuffle
  • Cortex
    • Setup
  • Shuffle
    • Setup
    • Workflows
      • Mimikatz Workflow
  • Case Studies
    • Mimikatz
      • Mimikatz execution
      • Wazuh rule
      • Shuffle workflow
  • Conclusion
    • Team
Powered by GitBook
On this page
  • Rising costs:
  • Manual Threat Investigation:
  • Limited Resources:
  • Alert Fatigue:

Was this helpful?

  1. Overview

Need for this project

Rising costs:

Modern SOC solutions require huge sums of licensing money, something that small businesses or independent security practitioners cannot afford.

Manual Threat Investigation:

SOC workflows require manual creation and analysis of security alerts, leading to slow investigation period and eventually may lead to analyst fatigue.

Limited Resources:

Resource-constrained SOCs struggle to keep pace with the high volume of alerts, hindering their ability to prioritize and investigate critical incidents. Also as the study implies that budget constraints are also one of the challenges that the small scale companies face.

Alert Fatigue:

A high volume of false positives creates alert fatigue, hindering the identification of genuine threats

NextAim of this project

Last updated 1 year ago

Was this helpful?