security / soc
SOC — Security Operations Center
Triage, investigation, réponse à incident et detection engineering. 16 notes au total.
01Triage
Priorisation des alertes, faux positifs, escalade
02Investigation
Analyse de logs, réseau, endpoint, EDR
Analyse de logs — Windows & Linux
Sources de logs critiques, event IDs Windows, syslog Linux, corrélations SOC
soclogs
Investigation réseau — SOC
Analyse de flux réseau, détection C2, beaconing, tunneling DNS/HTTPS
socnetwork
Investigation endpoint — EDR & Artefacts
Analyser les artefacts endpoint : processus, persistance, mémoire, timeline
socendpoint
03Réponse
IR playbook, confinement, analyse malware
Shuffle — SOAR Open Source
Déploiement et configuration de Shuffle SOAR : workflows d'automatisation SOC, apps, triggers, intégration TheHive/Wazuh/MISP
shufflesoar
n8n — Automatisation de Workflows SOC
n8n comme SOAR léger : workflows d'automatisation SOC, intégration Wazuh/TheHive/MISP, alertes et réponses automatisées
n8nsoar
TheHive — Gestion d'incidents & Cases
Déploiement et utilisation de TheHive 5 pour la gestion d'incidents SOC : cases, alertes, observables, Cortex
thehivesoc
Réponse à incident — Playbook
Phases IR, containment, éradication, recovery — guide SOC
socincident-response
Analyse de malware — Triage rapide
Analyse statique et dynamique de malware, sandbox, IOC extraction
socmalware
04Détection
Règles Sigma, SIEM tuning, detection engineering
OpenCTI — Threat Intelligence Platform
Déploiement et utilisation d'OpenCTI : graphe de connaissance cyber, gestion des acteurs/TTP/IOC, intégration MISP et connecteurs
openctithreat-intelligence
MITRE D3FEND — Contre-mesures Défensives
Framework MITRE D3FEND : taxonomie des techniques défensives, mapping avec ATT&CK, posture management et hardening
d3fendmitre
MISP — Threat Intelligence & Partage d'IOC
Déploiement MISP, gestion des événements, partage d'IOC, intégration TheHive et feeds automatisés
mispthreat-intelligence
MITRE ATT&CK — Matrice & Détection
Framework MITRE ATT&CK : 14 tactiques, techniques clés, mapping vers règles Sigma/SIEM et ATT&CK Navigator
mitreattck
Règles Sigma — Détection SOC
Écrire, convertir et déployer des règles Sigma pour SIEM
socsigma
OPS·BRAIN v1.092 notes · Securitylocal