Collect meaningful telemetry
Firewall, IDS, endpoint, and network visibility are brought together to improve the quality of security decisions.
Open-source SOC engineering project
SynapticSOC is an independently built cybersecurity engineering project designed, integrated, and documented using real hardware, real telemetry, and realistic resource constraints.
The Project
SynapticSOC explores what it takes to make open-source security tools function as one connected operational system, rather than a collection of isolated dashboards.
Firewall, IDS, endpoint, and network visibility are brought together to improve the quality of security decisions.
Alerts are enriched and compared against pfSense, Zeek, Wazuh, and Graylog evidence before an analyst response is recommended.
Triage, acknowledgment, and response steps are designed to leave a clear record of what was observed and why action was taken.
Architecture
The architecture is designed around telemetry quality, practical integration, and clear analyst workflow.
Current Capabilities
The project is documented around capabilities that have been implemented, observed, and validated.
Network events are collected from pfSense, Snort, and Suricata.
Wazuh agents provide host-level events, detections, and context.
Zeek visibility helps determine whether observed traffic reached an endpoint.
n8n workflows enrich alerts and support structured analyst acknowledgment.
Build Journal
The journal will document the problems, failures, decisions, and lessons involved in building the project.
A practical account of the challenges involved in using Zeek to validate whether IDS-observed traffic reached an internal host.
How enrichment, correlation, acknowledgment, and evidence retention were approached without over-automating response.
About SynapticSOC
SynapticSOC is built and documented as a technical portfolio, learning platform, and foundation for future open-source SOC research, education, and collaboration.