Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple

Autores/as

  • Jose Fernando Espinoza Leon Servicio Nacional de Adiestramiento en Trabajo Industrial (SENATI), Perú

DOI:

https://doi.org/10.18687/LACCEI2026.1.1.1425

Palabras clave:

Security Operations Center, SIEM, Kali Purple, Open-Source Software, Threat Detection, Incident Response.

Resumen

The increasing sophistication of cyber threats has intensified the need for proactive monitoring, detection, and response mechanisms within Security Operations Centers (SOCs). This paper presents the design and experimental implementation of a SOC laboratory environment based on Kali Purple, aimed at evaluating the effectiveness of Free and Open Source Software (FOSS) security technologies. The proposed environment integrates open-source SIEM and network monitoring solutions, including Wazuh and Suricata, complemented by the Elastic Stack for log analysis and visualization, Zeek for advanced network traffic inspection, and TheHive for incident response management. Controlled attack scenarios were conducted, including SSH brute-force attempts, DNS-based data exfiltration, and HTTP-based malware command-and-control communications, in order to assess detection accuracy, alert correlation, and response workflows. The experimental results indicate that properly configured FOSS-based SIEM solutions are capable of providing effective threat detection, situational awareness, and incident response in small- and medium-scale organizational environments, highlighting their viability as cost-effective alternatives for cybersecurity monitoring, training, and applied research.

Descargas

Publicado

2026-07-27

Número

Sección

Articles

Licencia

Licencia Creative Commons

Esta obra está bajo una Licencia Creative Commons Atribución-NoComercial-CompartirIgual 4.0 Internacional.

LACCEI conserva el copyright de todos los artículos publicados bajo los términos de su acuerdo de transferencia de copyright. Como titular del copyright, LACCEI distribuye los artículos al público bajo la Licencia Internacional Creative Commons Atribución-NoComercial-CompartirIgual 4.0 (CC BY-NC-SA 4.0).

Cómo citar

Espinoza Leon, J. F. (2026). Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple. LACCEI, 1(14). https://doi.org/10.18687/LACCEI2026.1.1.1425