Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple
DOI:
https://doi.org/10.18687/LACCEI2026.1.1.1425Palabras clave:
Security Operations Center, SIEM, Kali Purple, Open-Source Software, Threat Detection, Incident Response.Resumen
The increasing sophistication of cyber threats has intensified the need for proactive monitoring, detection, and response mechanisms within Security Operations Centers (SOCs). This paper presents the design and experimental implementation of a SOC laboratory environment based on Kali Purple, aimed at evaluating the effectiveness of Free and Open Source Software (FOSS) security technologies. The proposed environment integrates open-source SIEM and network monitoring solutions, including Wazuh and Suricata, complemented by the Elastic Stack for log analysis and visualization, Zeek for advanced network traffic inspection, and TheHive for incident response management. Controlled attack scenarios were conducted, including SSH brute-force attempts, DNS-based data exfiltration, and HTTP-based malware command-and-control communications, in order to assess detection accuracy, alert correlation, and response workflows. The experimental results indicate that properly configured FOSS-based SIEM solutions are capable of providing effective threat detection, situational awareness, and incident response in small- and medium-scale organizational environments, highlighting their viability as cost-effective alternatives for cybersecurity monitoring, training, and applied research.Descargas
Publicado
2026-07-27
Número
Sección
Articles
Derechos de autor
Derechos de autor 2026 LACCEI
Licencia
Esta obra está bajo una Licencia Creative Commons Atribución-NoComercial-CompartirIgual 4.0 Internacional.
LACCEI conserva el copyright de todos los artículos publicados bajo los términos de su acuerdo de transferencia de copyright. Como titular del copyright, LACCEI distribuye los artículos al público bajo la Licencia Internacional Creative Commons Atribución-NoComercial-CompartirIgual 4.0 (CC BY-NC-SA 4.0).
Cómo citar
Espinoza Leon, J. F. (2026). Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple. LACCEI, 1(14). https://doi.org/10.18687/LACCEI2026.1.1.1425