<< Back

Cyberattack Detection and Mitigation in a Security Operations Center (SOC) Using Free Software SIEM Tools in Kali Purple (#1425)

Read Article

Date of Conference

July 15-17, 2026

Published In

"Engineering without Borders: Artificial Intelligence, Knowledge, Innovation, and Alliances for a Future from the Americas"

Location of Conference

Santiago (Chile)

Authors

Espinoza Leon, Jose Fernando

Abstract

The increasing sophistication of cyber threats has intensified the need for proactive monitoring, detection, and response mechanisms within Security Operations Centers (SOCs). This paper presents the design and experimental implementation of a SOC laboratory environment based on Kali Purple, aimed at evaluating the effectiveness of Free and Open Source Software (FOSS) security technologies. The proposed environment integrates open-source SIEM and network monitoring solutions, including Wazuh and Suricata, complemented by the Elastic Stack for log analysis and visualization, Zeek for advanced network traffic inspection, and TheHive for incident response management. Controlled attack scenarios were conducted, including SSH brute-force attempts, DNS-based data exfiltration, and HTTP-based malware command-and-control communications, in order to assess detection accuracy, alert correlation, and response workflows. The experimental results indicate that properly configured FOSS-based SIEM solutions are capable of providing effective threat detection, situational awareness, and incident response in small- and medium-scale organizational environments, highlighting their viability as cost-effective alternatives for cybersecurity monitoring, training, and applied research.

Read Article