The SOC Case

Project Info:

The SOC Case was an individual project where I had to set up a fully functional Security Operations Center (SOC) in the school’s datacenter. Using VMware, I installed the entire network environment along with the necessary servers.

The project started from a blank slate with a list of open-source tools that I was free to choose from. This gave me the freedom to design the SOC architecture entirely on my own, tailored to my interests and insights in cybersecurity. Among the tools I selected were pfSense, Wazuh, IRIS, Shuffle, and Telegram integrations to enable alerts and automations.

After setting up the SOC, the goal was to simulate and demonstrate two attack scenarios. By analyzing these realistic attacks and responding with my custom-built systems, I gained deep hands-on experience in detection, monitoring, and incident response. The project combined technical infrastructure setup with practical cybersecurity skills, providing me with a strong understanding of how a SOC operates in real-world conditions.

Project Details:

  • Technologies:Wazuh, pfSense, Shuffle, IRIS, Ubuntu/linux, Telegram Bot API, VMware ESXi
  • Date:November 2025 - Januari 2025
  • Documentation:Open here