Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple
DOI:
https://doi.org/10.18687/LACCEI2026.1.1.1425Keywords:
Security Operations Center, SIEM, Kali Purple, Open-Source Software, Threat Detection, Incident Response.Abstract
The increasing sophistication of cyber threats has intensified the need for proactive monitoring, detection, and response mechanisms within Security Operations Centers (SOCs). This paper presents the design and experimental implementation of a SOC laboratory environment based on Kali Purple, aimed at evaluating the effectiveness of Free and Open Source Software (FOSS) security technologies. The proposed environment integrates open-source SIEM and network monitoring solutions, including Wazuh and Suricata, complemented by the Elastic Stack for log analysis and visualization, Zeek for advanced network traffic inspection, and TheHive for incident response management. Controlled attack scenarios were conducted, including SSH brute-force attempts, DNS-based data exfiltration, and HTTP-based malware command-and-control communications, in order to assess detection accuracy, alert correlation, and response workflows. The experimental results indicate that properly configured FOSS-based SIEM solutions are capable of providing effective threat detection, situational awareness, and incident response in small- and medium-scale organizational environments, highlighting their viability as cost-effective alternatives for cybersecurity monitoring, training, and applied research.Downloads
Published
2026-07-27
Issue
Section
Articles
Copyright
Copyright (c) 2026 LACCEI
License
This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
LACCEI retains copyright of all published articles under the terms of its copyright transfer agreement. As the copyright holder, LACCEI distributes the articles to the public under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).
How to Cite
Espinoza Leon, J. F. (2026). Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple. LACCEI, 1(14). https://doi.org/10.18687/LACCEI2026.1.1.1425