The SOC Automation Project aimed to create a robust and automated SOC environment capable of effectively detecting, analyzing, and responding to security incidents The primary focus remains on detecting Mimikatz, utilizing Wazuh for SIEM,Windows 10 agents, TheHive for case management, and now incorporating Shuffle with SOAR workflows.
- Advanced understanding of SIEM concepts and practical application.
- Proficiency in analyzing and interpreting network logs.
- Ability to generate and recognize attack signatures and patterns.
- Enhanced knowledge of network protocols and security vulnerabilities.
- Development of critical thinking and problem-solving skills in cybersecurity.
- Security Information and Event Management (SIEM) system for log ingestion and analysis.
- Network analysis tools (such as Wireshark) for capturing and examining network traffic.
- Telemetry generation tools to create realistic network traffic and attack scenarios.