Section 01
Practical Open-Source Intelligent SOC System: Building an Automated Security Operations Center with Wazuh+Suricata+Machine Learning (Introduction)
This article introduces an intelligent Security Operations Center (SOC) project built using an open-source tech stack (Wazuh, Suricata, pfSense, etc.) and machine learning (Random Forest + Isolation Forest), aiming to provide a practical cybersecurity monitoring solution for small and medium-sized enterprises. The project covers architecture design, component integration, ML model training, and automated response mechanisms. It is a cybersecurity graduation project from TEK-UP University in Tunisia, authored by Amir Ghediri, with the code open-sourced on GitHub (link: https://github.com/emirghdiri/Intelligent-SOC-System). The core goal is to achieve enterprise-level security monitoring capabilities using open-source tools and reduce operational costs.