Attributing intelligence to the information security area has become a mandatory measure for knowing what is controlled within the organization, creating new models of cybernetic defense, not only based on the behavior of anomalies in the company, but also on what is happening around the world. This article presents an introductory SOC model capable of performing the necessary operations for monitoring threats and anomalies within an organization's network assets, emphasizing SIEM technology. For the tests with the technology, a laboratory was built so that the tests could be carried out in a practical way, assembling and simulating the SIEM Wazuh servers according to the official documentation and the good practices defined by the developers, as well as the necessary infrastructure to simulate the security incident composed of endpoint, firewall and SIEM servers (Indexer, Server and Dashboard). With the tests carried out in the laboratory, it was possible to create a monitoring environment capable of detecting anomalies as predicted by the technology, allowing the creation of new detection rules and integration of different data sources, Wazuh as a SIEM presents itself as a solution of lowcost cost effective for incident detection.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.