The Project

SynapticSOC

A self-hosted SOC operating model built with open-source security tools — from perimeter sensor to audit record, integrating IDS alerts, firewall telemetry, passive network visibility, and endpoint detection into a correlated triage pipeline with controlled automation, access separation, evidence handling, retention policy, and audit-ready controls.

What It Is

A practical SOC operating model, not a tool showcase

SynapticSOC is an operational Security Operations Center project built under real-world infrastructure and resource constraints. It is not presented as a commercial SOC platform, managed detection service, certified compliance environment, or disposable lab exercise. It is a working SOC operating model designed to show how security telemetry, detection, triage, automation, accountability, and governance controls can be brought together in a self-hosted environment.

01 / Visibility

Observe the environment

Firewall telemetry, IDS alerts, passive network visibility, and endpoint events are collected to support practical detection, investigation, and triage.

02 / Correlation

Review events in context

Alerts are correlated against supporting evidence from firewall, network, endpoint, and enrichment sources before any response decision is made.

03 / Accountability

Record the workflow

Analyst acknowledgment, audit records, retention documentation, and control summaries support traceability, management review, and audit-ready visibility.

Operating Model

Built with open-source tools, defined by integration and control

The project uses open-source security tools across perimeter security, network intrusion detection, passive network analysis, endpoint monitoring, log management, indexing, workflow automation, dashboarding, and analyst communication. Those tools provide the foundation. The SynapticSOC operating model defines how the components are integrated, correlated, controlled, documented, and governed.

Maturity Path

From visibility to audit-ready control documentation

SynapticSOC was built through a deliberate maturity path: operational capability first, governance and controls built on top. Each stage depended on the one before it.

Stage 01

Visibility

Firewall, IDS, passive network, and endpoint telemetry were established across the environment.

Stage 02

Detection

Detection sources were configured and validated. Log ingestion into the triage layer was stabilized.

Stage 03

Correlation

Multi-source correlation across firewall, IDS, passive network visibility, and endpoint events was introduced.

Stage 04

Controlled response

SOAR intake was introduced with automation deliberately constrained. No destructive automated response is permitted.

Stage 05

Analyst acknowledgment

A structured acknowledgment workflow was introduced. Alert review is recorded and traceable, not assumed.

Stage 06

RBAC and access control

Role separation and least-privilege access boundaries were implemented and validated across SOC platforms.

Stage 07

Evidence handling

Evidence classification, lifecycle, chain-of-custody considerations, and public-safe redaction were formalized.

Stage 08

Retention policy

Differentiated retention for raw telemetry and audit records was documented and validated across the stack.

Stage 09

Audit-ready control pack

RBAC, evidence handling, and retention controls were consolidated into a single integrated control reference.

Phase 1.5

Zeek visibility hardening

Before publication, a targeted hardening update addressed a known timing gap in the Zeek correlation layer. SOC/01 v1.7 introduced a two-pass Zeek lookup — immediate, then deferred after 120 seconds — producing three classified outcomes: zeek_seen_immediate, zeek_seen_deferred, and zeek_no_match_after_delay. Visibility gap results are written into Graylog audit records through structured GELF writeback.

Detection and Triage

The technical center of the SOC

At the center of SynapticSOC is the detection and triage pipeline. IDS alerts provide the intake trigger. Firewall telemetry adds perimeter and pass/block context. Passive network monitoring contributes flow and protocol visibility across the monitored segment. Endpoint monitoring adds host-level detection and security context. External IP enrichment supports reputation-aware review. Correlation and controlled automation then bring those signals into a structured analyst workflow without permitting destructive automated response.

Firewall telemetry

pfSense events support network boundary context, pass/block visibility, and edge-level review.

IDS alerting

Snort and Suricata provide signature-based detection coverage at the network layer.

Passive network visibility

Zeek contributes flow-level and protocol evidence across the monitored LAN segment.

Endpoint monitoring

Wazuh provides host-level visibility, alerting, vulnerability findings, and compliance-oriented context.

Log aggregation and triage

Graylog provides parsing, stream organization, enrichment, evidence review, and analyst-facing triage views.

Controlled SOAR

n8n handles controlled intake, triage routing, analyst notification, acknowledgment, and audit writeback without autonomous destructive action.

Control Model

Controls that make the SOC defensible

SynapticSOC is governed by operational controls that support role separation, analyst accountability, evidence traceability, retention documentation, and audit-ready visibility.

Control 01

RBAC and access separation

Least-privilege roles and validated access boundaries across Graylog, Wazuh, Grafana, n8n, and backend infrastructure.

Control 02

Evidence handling

Defined classification, lifecycle, chain-of-custody considerations, redaction rules, and public/private evidence separation.

Control 03

Retention policy

Differentiated retention for raw telemetry, audit records, workflow history, endpoint evidence, and documentation artifacts.

Limitations

Clear boundaries and honest non-claims

SynapticSOC does not claim certified compliance with any regulatory framework, legal-grade forensic chain of custody, immutable archival storage, enterprise high availability, commercial SOC replacement capability, managed detection and response maturity, or full case management capability. Its value is in practical SOC engineering under real constraints, transparent documentation, and honest control development.

Documentation

Read the full whitepaper

The SynapticSOC whitepaper documents the architecture, component roles, detection and visibility pipeline, controlled SOAR workflow, analyst acknowledgment model, RBAC, evidence handling, retention policy, management dashboards, final control pack, limitations, and roadmap. It is designed for public portfolio and GitHub use without exposing sensitive infrastructure details or private validation artifacts.