As our capstone project, we designed and developed a Security Operations Center (SOC) using open-source technologies to demonstrate how organizations can strengthen their cybersecurity posture without relying on expensive commercial solutions. The project focused on building a centralized environment capable of collecting, monitoring, and analyzing security events from different systems, providing real-time visibility into potential threats and suspicious activities.
The SOC was implemented by integrating industry-recognized open-source tools for security monitoring, log management, and threat detection. We configured endpoints to forward security logs to a central platform, created monitoring dashboards, and developed detection rules to identify common attack patterns and security incidents. The project also involved setting up a virtualized lab environment to simulate real-world scenarios, allowing us to validate detections and gain practical experience in incident monitoring and analysis.
Through this project, we gained hands-on experience in SOC architecture, system administration, log analysis, security monitoring, and incident response workflows. Beyond the technical implementation, the capstone reinforced the importance of automation, visibility, and continuous monitoring in modern cybersecurity operations. It demonstrated that a functional and effective Security Operations Center can be built using freely available tools, making enterprise-level security practices more accessible to educational institutions, small businesses, and organizations with limited budgets.