// cat ./projects/soc-automation.md
SOC Automation & Visualization
TheHive + Elasticsearch + Grafana + n8n
A dockerized SOC stack with n8n workflow orchestration — case management, detection backbone, and dashboards that small teams can stand up in under a day.
## Stack
TheHive for case management, Elasticsearch as the detection backbone, Grafana for attack visualization, and n8n as the workflow fabric tying everything to upstream alert sources.
## Why n8n over enterprise SOAR
Enterprise SOAR pricing kills small SOCs. n8n delivers 90% of the orchestration value at zero license cost, with workflows that engineers can read, version, and extend in Git.
## Workflows
n8n flows triage incoming alerts, enrich them with threat intel, open cases in TheHive, and notify the on-call channel — collapsing manual triage from minutes to seconds.
## Outcome
A reproducible SOC blueprint with a clear upgrade path toward enterprise SIEM tooling when scale demands it.
// ls ../
FLAGSHIP
Snock →
Autonomous Cloud Security AI Agent
RESEARCH
SpecterHeal →
AI-Assisted Self-Healing Infrastructure
PRODUCTION
Enterprise DDoS Defense →
AWS Shield Advanced & Firewall Manager Automation
PRODUCTION
Hardened GitLab DevSecOps Platform →
Secure CI/CD with Terraform, tfsec, Trivy, SonarQube
ENGAGEMENT
Trend Micro XDR Remediation →
Enterprise Endpoint Detection & Response Tuning
PRODUCTION
AWS Incident Response Automation →
Event-Driven Containment with Lambda + CloudWatch
PRODUCTION
Fortinet SD-WAN Deployment →
Resilient Multi-Site Connectivity
INTERNAL
CTF Training Platform →
Practical Cybersecurity Training Lab
PRODUCTION
Cloud Monitoring & Observability Platform →
Terraform, ECS Fargate, cross-account CloudWatch
DELIVERED
CIS Benchmark & Remediation Program →
Measured posture improvement across a DevOps platform
DELIVERED
Open Banking Auth Flow Load Testing →
k6, mTLS, FAPI/OAuth2 with PAR, browser-driven SCA