Observe the environment
Firewall telemetry, IDS alerts, passive network visibility, and endpoint events are collected to support practical detection, investigation, and triage.
The Project
A self-hosted SOC operating model built with open-source security tools — from perimeter sensor to audit record, integrating IDS alerts, firewall telemetry, passive network visibility, and endpoint detection into a correlated triage pipeline with controlled automation, access separation, evidence handling, retention policy, and audit-ready controls.
What It Is
SynapticSOC is an operational Security Operations Center project built under real-world infrastructure and resource constraints. It is not presented as a commercial SOC platform, managed detection service, certified compliance environment, or disposable lab exercise. It is a working SOC operating model designed to show how security telemetry, detection, triage, automation, accountability, and governance controls can be brought together in a self-hosted environment.
Firewall telemetry, IDS alerts, passive network visibility, and endpoint events are collected to support practical detection, investigation, and triage.
Alerts are correlated against supporting evidence from firewall, network, endpoint, and enrichment sources before any response decision is made.
Analyst acknowledgment, audit records, retention documentation, and control summaries support traceability, management review, and audit-ready visibility.
Operating Model
The project uses open-source security tools across perimeter security, network intrusion detection, passive network analysis, endpoint monitoring, log management, indexing, workflow automation, dashboarding, and analyst communication. Those tools provide the foundation. The SynapticSOC operating model defines how the components are integrated, correlated, controlled, documented, and governed.
Maturity Path
SynapticSOC was built through a deliberate maturity path: operational capability first, governance and controls built on top. Each stage depended on the one before it.
Firewall, IDS, passive network, and endpoint telemetry were established across the environment.
Detection sources were configured and validated. Log ingestion into the triage layer was stabilized.
Multi-source correlation across firewall, IDS, passive network visibility, and endpoint events was introduced.
SOAR intake was introduced with automation deliberately constrained. No destructive automated response is permitted.
A structured acknowledgment workflow was introduced. Alert review is recorded and traceable, not assumed.
Role separation and least-privilege access boundaries were implemented and validated across SOC platforms.
Evidence classification, lifecycle, chain-of-custody considerations, and public-safe redaction were formalized.
Differentiated retention for raw telemetry and audit records was documented and validated across the stack.
RBAC, evidence handling, and retention controls were consolidated into a single integrated control reference.
Phase 1.5
Before publication, a targeted hardening update addressed a known timing gap in the Zeek
correlation layer. SOC/01 v1.7 introduced a two-pass Zeek lookup — immediate, then deferred
after 120 seconds — producing three classified outcomes: zeek_seen_immediate,
zeek_seen_deferred, and zeek_no_match_after_delay. Visibility
gap results are written into Graylog audit records through structured GELF writeback.
Detection and Triage
At the center of SynapticSOC is the detection and triage pipeline. IDS alerts provide the intake trigger. Firewall telemetry adds perimeter and pass/block context. Passive network monitoring contributes flow and protocol visibility across the monitored segment. Endpoint monitoring adds host-level detection and security context. External IP enrichment supports reputation-aware review. Correlation and controlled automation then bring those signals into a structured analyst workflow without permitting destructive automated response.
pfSense events support network boundary context, pass/block visibility, and edge-level review.
Snort and Suricata provide signature-based detection coverage at the network layer.
Zeek contributes flow-level and protocol evidence across the monitored LAN segment.
Wazuh provides host-level visibility, alerting, vulnerability findings, and compliance-oriented context.
Graylog provides parsing, stream organization, enrichment, evidence review, and analyst-facing triage views.
n8n handles controlled intake, triage routing, analyst notification, acknowledgment, and audit writeback without autonomous destructive action.
Control Model
SynapticSOC is governed by operational controls that support role separation, analyst accountability, evidence traceability, retention documentation, and audit-ready visibility.
Least-privilege roles and validated access boundaries across Graylog, Wazuh, Grafana, n8n, and backend infrastructure.
Defined classification, lifecycle, chain-of-custody considerations, redaction rules, and public/private evidence separation.
Differentiated retention for raw telemetry, audit records, workflow history, endpoint evidence, and documentation artifacts.
Limitations
SynapticSOC does not claim certified compliance with any regulatory framework, legal-grade forensic chain of custody, immutable archival storage, enterprise high availability, commercial SOC replacement capability, managed detection and response maturity, or full case management capability. Its value is in practical SOC engineering under real constraints, transparent documentation, and honest control development.
Documentation
The SynapticSOC whitepaper documents the architecture, component roles, detection and visibility pipeline, controlled SOAR workflow, analyst acknowledgment model, RBAC, evidence handling, retention policy, management dashboards, final control pack, limitations, and roadmap. It is designed for public portfolio and GitHub use without exposing sensitive infrastructure details or private validation artifacts.