{"id":44939,"url":"https://github.com/cyb3rxp/awesome-soc","name":"awesome-soc","description":"A curated knowledge base to build, run and mature a SOC (including CSIRT).","projects_count":150,"last_synced_at":"2026-09-30T15:00:29.211Z","repository":{"id":63561793,"uuid":"528122769","full_name":"cyb3rxp/awesome-soc","owner":"cyb3rxp","description":"A curated knowledge base to build, run and mature a SOC (including CSIRT).","archived":false,"fork":false,"pushed_at":"2026-08-26T13:31:32.000Z","size":23717,"stargazers_count":1865,"open_issues_count":4,"forks_count":298,"subscribers_count":42,"default_branch":"main","last_synced_at":"2026-09-10T18:59:11.718Z","etag":null,"topics":["architecture","cert","csirt","cybersecurity","detection-engineering","dfir","incident-response","mitre-attack","purpleteam","risk-management","security-monitoring","siem","sirp","soar","soc","threat-detection","threat-hunting","tip","ttp"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cyb3rxp.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null}},"created_at":"2022-08-23T18:47:53.000Z","updated_at":"2026-09-10T12:49:22.000Z","dependencies_parsed_at":"2026-08-11T17:25:01.720Z","dependency_job_id":null,"html_url":"https://github.com/cyb3rxp/awesome-soc","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/cyb3rxp/awesome-soc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyb3rxp%2Fawesome-soc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyb3rxp%2Fawesome-soc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyb3rxp%2Fawesome-soc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyb3rxp%2Fawesome-soc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cyb3rxp","download_url":"https://codeload.github.com/cyb3rxp/awesome-soc/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cyb3rxp%2Fawesome-soc/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":342085742,"owners_count":37879827,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-09-30T02:00:06.001Z","response_time":133,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-01-13T21:19:01.766Z","updated_at":"2026-09-30T15:00:29.211Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["SOC sensors, nice to have","Must read","Critical tools for CSIRT","Recommended sources","Globally (SOC and CERT/CSIRT)","Nice to read","Critical tools for a SOC/CSIRT","📖 **Nice to Read**","Other critical tools for a SOC and a CERT/CSIRT","For a CERT/CSIRT","For a SOC","SOC and CSIRT core","SOC core","Critical sensors for a SOC","Have a single and centralized platform ('single console')","Disconnect (as much as possible) SOC from monitored environment","Harden SOC/CSIRT environment","License","📚 **Must Read**"],"sub_categories":["Endpoints hardening:","SOC architecture of detection","**Miscellaneous Resources**","From logs to alerts: global generic workflow","SOC/CSIRT architecture of detection","Enclave:","**Frameworks \u0026 Methodologies**","**Threat Intelligence**","**Compliance \u0026 Regulations**","**Tools \u0026 Architectures**","**Use Cases \u0026 Implementations**","**Standards \u0026 Controls**","**Cloud \u0026 Platforms**","**Incident Response**","**SOC Tools \u0026 Architectures**","**Benchmarks \u0026 Surveys**"],"readme":"![GitHub stars](https://img.shields.io/github/stars/cyb3rxp/awesome-soc?style=social) [![Awesome](https://awesome.re/badge.svg)](https://awesome.re) ![Last Update](https://img.shields.io/github/last-commit/cyb3rxp/awesome-soc) ![License](https://img.shields.io/github/license/cyb3rxp/awesome-soc) ![Contributions welcome](https://img.shields.io/badge/contributions-welcome-brightgreen) ![Lychee](https://github.com/cyb3rxp/awesome-soc/actions/workflows/link-check.yml/badge.svg)\n# Awesome SOC\n\nAn operational handbook and knowledge base to build, run and mature a SOC (including CSIRT). Covering:\n- SOC basics\n- detection engineering\n- threat intelligence\n- SOC metrics/KPI\n- SOC automation\n- AI use cases and best practices\n- SOP (SOC playbooks)\n\nThose are my view, based on my own experience as SOC/CSIRT analyst and team manager, as well as well-known papers. Focus is more on SOC than on CERT/CSIRT.\n\nMy motto is: without reaction (response), detection is useless.\n\nNB: Generally speaking, SOC here refers to detection activity, and CERT/CSIRT to incident response activity. CERT is a well-known (formerly) US trademark, managed by [CERT-CC](https://www.sei.cmu.edu/divisions/cert/), but I prefer the term [CSIRT](https://www.enisa.europa.eu/sites/default/files/publications/Incident_Management_guide.pdf) as it precisely refers to incident response.\n\n\n# Table of Contents\n* [Must read](#must-read)\n* [Fundamental concepts](#Fundamental-concepts)\n* [Mission-critical means (tools/sensors)](#mission-critical-means-toolssensors)\n* [SOC internals/core](#soc-internals)\n* [AI (ML, LLM, GenAI, Agentic AI)](#AI)\n* [IT/security Watch](#itsecurity-watch)\n* [SOAR](#SOAR)\n* [Detection engineering](#detection-engineering)\n* [Threat intelligence](#threat-intelligence)\n* [Playbooks/SOP](#playbooks)\n* [SOC metrics (KPI/SLA)](#soc-metrics-kpisla)\n* [SOC Management](#management)\n* [HR and training](#hr-and-training)\n* [IT achitecture](#it-achitecture-of-a-soc)\n* [To go further (next steps)](#to-go-further)\n* [Appendix](#appendix)\n\n# Must read\n\n## For a SOC\n* **SOC build**:\n  * MITRE, [11 strategies for a world-class SOC](https://www.mitre.org/publications/technical-papers/11-strategies-world-class-cybersecurity-operations-center) (or use [local file](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf)): part 0 (Fundamentals).\n  * FIRST, [Building a SOC](https://www.first.org/resources/guides/Factsheet_Building_a_SOC_start_small.pdf)\n  * NCSC, [Building a SOC](https://www.ncsc.gov.uk/collection/building-a-security-operations-centre)\n  * Gartner, [SOC model guide](https://fr.scribd.com/document/732782046/Gartner-SOC-Model-Guide-2023)\n  * Splunk, [State of Security 2025](https://www.splunk.com/en_us/pdfs/gated/ebooks/state-of-security-2025.pdf)\n  * Microsoft, [Secure your business with 365](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/m365b-security-best-practices?view=o365-worldwide) \n* **SOC training for interview**:\n  * LetsDefend [SOC analyst interview questions](https://github.com/LetsDefend/SOC-Interview-Questions)\n* **SOC management**:\n  * FIRST, [ISO 27035 Practical value for CSIRT and SOCs ](https://www.first.org/resources/papers/conf2023/FIRSTCON23-TLPCLEAR-Benetis-ISO-27035-practical-value-for-CSIRTs-and-SOCs.pdf)\n  * SANS, [2025 SOC survey](https://www.elastic.co/pdf/sans-soc-survey-2025.pdf)\n  * SOC CMM, [SOC Metrics](https://www.soc-cmm.com/img/upload/files/31-soc-cmm-metrics-101.pdf)\n* **SOC assessment**:\n  * CMM, [SOC-CMM](https://www.soc-cmm.com/)\n  * Rabobank CDC, [DeTTECT](https://github.com/rabobank-cdc/DeTTECT)\n  * SANS, [Continous purple teaming](https://www.sans.org/blog/continuous-purple-teaming-practical-approach-strengthening-offensive-capabilities)\n\n\n## For a CERT/CSIRT\n* **Global overview**:\n  * SANS, [Incident Response](https://www.sans.org/security-resources/glossary-of-terms/incident-response)\n  * FlexibleIR, [IR phases](https://playbooks.flexibleir.com/incident-response-phases-best-practices/)\n* **CSIRT build**:\n  * FIRST, [CERT-in-a-box](https://www.first.org/resources/guides/cert-in-a-box.zip) \n  * FIRST, [CSIRT Services Framework](https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1)\n* **Security incident response management**:\n  * ENISA, [Good practice for incident management](https://www.enisa.europa.eu/publications/good-practice-guide-for-incident-management)\n  * EE-ISAC [Incident Response whitepaper](https://www.ee-isac.eu/media/2023/05/EE-ISAC-Incident-Response-White-Paper.pdf)\n  * LinkedIn Pulse, [Security incident management according to ISO 27035](https://www.linkedin.com/pulse/security-incident-management-according-iso-27035-dipen-das-)\n  * Microsoft/EY/Edelman, [Incident response reference guide](https://www.linkedin.com/posts/the-cyber-security-hub_incident-response-reference-guide-activity-7033563558642642944-0zav?utm_source=share\u0026utm_medium=member_desktop)\n  * Microsoft, [IR lessons on cloud ID compromise](https://www.microsoft.com/en-us/security/blog/2023/12/05/microsoft-incident-response-lessons-on-preventing-cloud-identity-compromise/?msockid=07788c7fcb0c689a2a5d98f6ca0169fb)\n* **Forensics**:\n  * NIST, [SP800-86, integration forensics techniques into IR](https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-86.pdf)\n  * [ForensicsArtefacts](https://github.com/ForensicArtifacts/artifacts)\n  * [ForensicsWiki](https://forensics.wiki/)\n* **Incident response playbooks \u0026 methodology**:\n  * Kaspersky, [Incident Response Playbook: Dark Web Breaches](https://dfi.kaspersky.com/blog/dark-web-threats-response-guideline#form)\n  * CISA, [Incident Response playbooks](https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf)\n  * CERT-SG, [Incident Response Methodology](https://github.com/certsocietegenerale/irm)\n\n## Globally (SOC and CERT/CSIRT)\n* **Processes and concepts**:\n  * PAN, [What is SecOps?](https://www.paloaltonetworks.com/cyberpedia/what-is-security-operations)\n  * Flavio Queiroz, [SecOPS vs. OPSEC](https://www.linkedin.com/pulse/clearing-fog-secops-vs-opsec-cybersecurity-flavio-queiroz--jfief/)\n  * Shubham, [Security 360](https://twitter.com/Shubham_pen/status/1655192003448020993?s=20)\n  * Vilius Benetis, [CSIRT, SOC, ISAC and PSIRT definitions](https://www.linkedin.com/pulse/csirt-soc-isac-psirt-definitions-vilius-benetis)\n  * Thomas Roccia, [Visual Threat Intelligence](https://www.amazon.fr/Visual-Threat-Intelligence-Illustrated-Researchers/dp/B0C7JCF8XD)\n  * SentinelOne, [What is SecOps](https://www.sentinelone.com/cybersecurity-101/secops/?utm_content=white-paper\u0026utm_medium=paid-display\u0026utm_source=gdn-paid\u0026utm_campaign=emea-t1-en-g-dsa\u0026utm_term={demo-request}\u0026utm_campaignid=19179764064\u0026gclid=EAIaIQobChMItYzg5amQ_gIV6pBoCR1u0ACxEAAYAiAAEgJ1ofD_BwE)\n  * Purp1eW0lf, [Blue Team Notes](https://github.com/Purp1eW0lf/Blue-Team-Notes)\n  * PAN, [Security orchestration for dummies](https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/cortex-xsoar/Security-Orchestration-For-Dummies-Demisto-Special-Edition.pdf)\n  * ThreatConnect, [SIRP / SOA / TIP benefits](https://threatconnect.com/blog/realizing-the-benefits-of-security-orchestration-automation-and-response-soar/)\n  * Medium, [Compromise assessment methodology](https://evrenbey.medium.com/compromise-assessment-methodology-820910efb6a4)\n  * Hunt.io, [Threat hunting framework (PEAK)](https://hunt.io/glossary/peak-threat-hunting-framework)\n* **Incident response specific process/lifecycle**:\n  * NIST, [SP800-61 rev3, incident handling guide](https://csrc.nist.gov/pubs/sp/800/61/r3/ipd)\n* **CSIRT build**:\n  * ENISA, [How to set-up a CSIRT and SOC](https://www.enisa.europa.eu/publications/how-to-set-up-csirt-and-soc)\n* **Frameworks and materials**:\n  * MITRE, [ATT\u0026CK: Getting started](https://attack.mitre.org/resources/getting-started/)\n  * NIST, [Cybersecurity framework](https://www.nist.gov/cyberframework)\n  * FIRST, [CVSS v4 specs](https://www.first.org/cvss/v4-0/)\n  * CERT-EU, [CTI Framework](https://www.cert.europa.eu/publications/threat-intelligence/cyber-threat-intelligence-framework/)\n  * OASIS Open, [STIX](https://oasis-open.github.io/cti-documentation/stix/intro.html)\n  * FIRST, [TLP](https://www.first.org/tlp/) (intelligence sharing and confidentiality), and [PAP](https://cert.ssi.gouv.fr/csirt/sharing-policy/)\n  * CIS, [18 critical security controls](https://www.cisecurity.org/controls/cis-controls-list)\n* **Security capabilities mappings**:\n  * CTID, [Mappings explorer](https://center-for-threat-informed-defense.github.io/mappings-explorer/external/)\n* **Threat matrix**:\n  * Push Security, [SaaS attack matrix](https://github.com/pushsecurity/saas-attacks#the-saas-attacks-matrix)\n  * Microsoft, [Threat Matrix for Azure Storage services](https://microsoft.github.io/Threat-matrix-for-storage-services/)\n  * MITRE, [Threat Matrix for AI-systems](https://github.com/mitre/advmlthreatmatrix/blob/master/pages/adversarial-ml-threat-matrix.md#adversarial-ml-threat-matrix)\n* **SOAR solutions**:\n  * Swimlane, [Cyber Threat readiness report 2023](https://swimlane.com/wp-content/uploads/Cyber-Threat-Readiness-Report-2023.pdf);\n  * Gartner, [Market Guide for Security Orchestration, Automation and Response Solutions](https://fr.scribd.com/document/619736260/Gartner-Market-Guide-for-Security-Orchestration-Automation)\n* **NIS2**:\n  * NIS2Directive: [NIS2 10 main requirements](https://nis2directive.eu/nis2-requirements/) \n  * LinkedIn: [How will NIS2 impact your organization?](https://www.linkedin.com/pulse/how-eu-directive-nis2-impact-your-organization-anders-fleinert-larsen%3FtrackingId=Vq3GCGlOTXe1u0dllhn9MA%253D%253D/?_l=fr_FR)\n  * Microsoft, [NIS2 webinar](https://info.microsoft.com/CE-NoGEP-VDEO-FY24-10Oct-09-What-is-NIS20-and-how-to-prepare-your-organization-and-customers-for-it-SREVM23845_LP02-Thank-You---Standard-Hero.html)\n  * CyberArk: [NIS2, how to address the security control gaps](https://event.on24.com/eventRegistration/console/apollox/mainEvent?simulive=y\u0026eventid=4110743\u0026sessionid=1\u0026username=\u0026partnerref=\u0026format=fhvideo1\u0026mobile=\u0026flashsupportedmobiledevice=\u0026helpcenter=\u0026key=588150776CAE70D7F02ECF2848FF11FA\u0026newConsole=true\u0026nxChe=true\u0026newTabCon=true\u0026consoleEarEventConsole=false\u0026text_language_id=en\u0026playerwidth=748\u0026playerheight=526\u0026eventuserid=600843623\u0026contenttype=A\u0026mediametricsessionid=517006274\u0026mediametricid=5797475\u0026usercd=600843623\u0026mode=launch)\n  * ENISA: [NIS2 technical implementation guidance](https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance)\n* **AI (genAI, LLM, agentic AI): monitoring, threat landscape, management**:\n  * CSOOnline, [SOCs face a challenge as AI speeds alerts and threats](https://www.csoonline.com/article/4198016/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html?utm_date=20260721140359\u0026utm_campaign=CSO%20Security%20Leadership\u0026utm_content=slotno-1-readmore-The%20future%20of%20the%20security%20operations%20center%20may%20depend%20less%20on%20technology%20than%20on%20how%20well%20security%20leaders%20manage%20human%20attention%2C%20expertise%2C%20and%20resilience.\u0026utm_term=CSO%20US%20Editorial%20Newsletters\u0026utm_medium=email\u0026utm_source=Adestra\u0026aid=8242015\u0026huid=677465b3-4cd2-44f5-ba75-a9eb7364bc6c)\n  * ENISA, [FAICP](https://www.faicp-framework.com/): Framework for AI Cybersecurity Practices\n  * NIST, [Challenges to the Monitoring of Deployed AI Systems](https://www.nist.gov/news-events/news/2026/03/new-report-challenges-monitoring-deployed-ai-systems)\n  * NIST, [AI 100-1](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf)\n  * OWASP, [Top 10 for Agentic Applications](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)\n  * CISCO, [State of AI Security 2026](https://www.cisco.com/site/us/en/products/security/state-of-ai-security.html)\n  * ENISA, [ENISA's view on cybersecurity in the frontier AI era](https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era)\n  * Microsoft [Turning threat reports into detection insights with AI](https://www.microsoft.com/en-us/security/blog/2026/01/29/turning-threat-reports-detection-insights-ai/)\n* **Management**:\n  * Gartner, [Cybersecurity business value benchmark](https://emtemp.gcom.cloud/ngw/globalassets/en/doc/documents/775537-gartner-cybersecurity-business-value-benchmark-1st-generation.pdf)\n  * CrowdStrike, [State of SIEM market 2025](https://go.crowdstrike.com/rs/281-OBQ-266/images/Whitepaper2025StateofSIEMMarketCribl.pdf?version=0)\n  * Microsoft, [\"While the initial trigger event was a Distributed Denial-of-Service (DDoS) attack... initial investigations suggest that an error in the implementation of our defences amplified the impact of the attack rather than mitigating it\"](https://www.bbc.com/news/articles/c903e793w74o)\n* **SOP (Standard Operating Procedures)**:\n  * [Antimalware check SOP](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_malware_critical_controls.md)\n  * [M365/Azure compromise asssessment SOP](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_M365_compromise_assessment.md)\n  * [Web server compromise assessment SOP](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_web_server_compromise_assessment.md)\n\n\n# Fundamental concepts\n\n## Concepts, tools, missions, attack lifecycle, red/blue/purple teams\n\n## MITRE references\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 5: Prioritize Incident Response, pages 125-150,\n\u003e Prepare for handling incidents by defining incident categories, response steps, and escalation\npaths, and codifying those into SOPs and playbooks. Determine the priorities of incidents for\nthe organization and allocate the resources to respond. Execute response with precision and\ncare toward constituency mission and business.\n\n## 🔗 Dedicated page\nCf. [SOC/CSIRT Basic and fundamental concepts](https://github.com/cyb3rxp/awesome-soc/blob/main/soc_basics.md).\n\n\n# Mission-critical means (tools/sensors)\n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 7: Select and Collect the Right Data, pages 179-240,\n\u003e Choose data by considering relative value of different data types such as sensor and log data\ncollected by network and host systems, cloud resources, applications, and sensors. Consider\nthe trade-offs of too little data and therefore not having the relevant information available and\ntoo much data such that tools and analysts become overwhelmed.\n\n## 🔗 Dedicated page\nCf. [Mission-critical means](https://github.com/cyb3rxp/awesome-soc/blob/main/mission-critical-means.md)\n\n\n# SOC internals\n\n## MITRE reference\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 8: Leverage Tools to Support Analyst Workflow, pages 241-284,\n\u003e Consolidate and harmonize views into tools and data and integrate them to maximize SOC\nworkflow. Consider how the many SOC tools, including SIEM, UEBA, SOAR, and others fit\nin with the organization’s technical landscape, to include cloud and OT environments\n\n## 🔗 Dedicated page\nCf. [SOC internals/core](https://github.com/cyb3rxp/awesome-soc/blob/main/soc_internals.md)\n\n\n# AI\n\n## MITRE reference\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 8: Leverage Tools to Support Analyst Workflow, pages 241-284,\n\u003e Consolidate and harmonize views into tools and data and integrate them to maximize SOC\nworkflow. Consider how the many SOC tools, including SIEM, UEBA, SOAR, and others fit\nin with the organization’s technical landscape, to include cloud and OT environments\n\n## 🔗 Dedicated page\nCf. [AI (ML, LLM, Agentic AI...)](https://github.com/cyb3rxp/awesome-soc/blob/main/ml_llm_ai.md)\n\n\n# IT/security Watch \n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence, pages 151-176,\n\u003e Tailor the collection and use of cyber threat intelligence by analyzing the intersection of\nadversary information, organization relevancy, and technical environment to prioritize\ndefenses, monitoring, and other actions.\n\n## 🔗 Dedicated page\nCf. [Watch](https://github.com/cyb3rxp/awesome-soc/blob/main/watch.md)\n\n# SOAR\n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 8: Leverage Tools to Support Analyst Workflow, pages 241-284,\n\u003e Consolidate and harmonize views into tools and data and integrate them to maximize SOC\nworkflow. Consider how the many SOC tools, including SIEM, UEBA, SOAR, and others fit\nin with the organization’s technical landscape, to include cloud and OT environments.\n\n\n## 🔗 Dedicated page\nCf. [SOAR](https://github.com/cyb3rxp/awesome-soc/blob/main/soar.md)\n\n\n# Detection engineering\n\n## MITRE references\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 1: Know What You Are Protecting and Why, pages 27-40,\n\u003e Develop situational awareness through understanding the mission; legal regulatory\nenvironment; technical and data environment; user, user behaviors and service interactions;\nand the threat. Prioritize gaining insights into critical systems and data and iterate understanding\nover time.\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 7: Select and Collect the Right Data, pages 179-240, \n\u003e Choose data by considering relative value of different data types such as sensor and log data\ncollected by network and host systems, cloud resources, applications, and sensors. Consider\nthe trade-offs of too little data and therefore not having the relevant information available and\ntoo much data such that tools and analysts become overwhelmed.\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 11: Turn up the Volume by Expanding SOC Functionality, pages 319-356,\n\u003e Enhance SOC activities to include threat hunting, red teaming, deception, malware analysis,\nforensics, and/or tabletop exercises, once incident response is mature. Any of these can\nimprove the SOCs operating ability and increase the likelihood of finding more sophisticated\nadversaries.\n\n\n## 🔗 Dedicated page\nCf. [detection engineering](https://github.com/cyb3rxp/awesome-soc/blob/main/detection_engineering.md).\n\n\n# Threat intelligence\n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence, pages 101-123,\n\u003e Tailor the collection and use of cyber threat intelligence by analyzing the intersection of\nadversary information, organization relevancy, and technical environment to prioritize\ndefenses, monitoring, and other actions.\n\n## 🔗 Dedicated page\nCf. [threat intelligence](https://github.com/cyb3rxp/awesome-soc/blob/main/threat_intelligence.md).\n\n\n\n# Playbooks\n\nBased on experience, I propose a few SOP (Standard Operating Procedures), that one may want to call playbooks.\n\n## 🔗 Dedicated pages\n\n- [Windows malware critical controls](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_malware_critical_controls.md)\n- [Microsoft 365 and Entra ID compromise assessment](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_M365_compromise_assessment.md)\n- [Web server compromise assessment](https://github.com/cyb3rxp/awesome-soc/blob/main/sop_web_server_compromise_assessment.md)\n\n\n# Management\n\n## MITRE references\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 1: Know What You Are Protecting and Why, pages 27-40\n\u003e Develop situational awareness through understanding the mission; legal regulatory\nenvironment; technical and data environment; user, user behaviors and service interactions;\nand the threat. Prioritize gaining insights into critical systems and data and iterate understanding\nover time.\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 2: Give the SOC the Authority to Do Its Job, pages 41-50\n\u003e Empower the SOC to carry out the desired functions, scope, partnerships, and responsibilities\nthrough an approved charter and the SOCs alignment within the organization\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 3: Build a SOC Structure to Match Your Organizational Needs, pages 101-123\n\u003e Structure SOCs by considering the constituency, SOC functions and responsibilities, service\navailability, and any operational efficiencies gained by selecting one construct over another\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 9: Communicate Clearly, Collaborate Often, Share Generously, pages 285-298\n\u003e Engage within the SOC, with stakeholders and constituents, and with the broader cyber\ncommunity to evolve capabilities and contribute to the overall security of the broader\ncommunity.\n\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 11: Turn up the Volume by Expanding SOC Functionality, pages 319-356\n\u003e Enhance SOC activities to include threat hunting, red teaming, deception, malware analysis,\nforensics, and/or tabletop exercises, once incident response is mature. Any of these can\nimprove the SOCs operating ability and increase the likelihood of finding more sophisticated\nadversaries.\n\n\n## 🔗 Dedicated page\nCf. [Management](https://github.com/cyb3rxp/awesome-soc/blob/main/management.md).\n\n\n# SOC metrics (KPI/SLA)\n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 10: Measure Performance to Improve Performance, pages 301-318\n\u003e Determine qualitative and quantitative measures to know what is working well, and where to\nimprove. A SOC metrics program includes business objectives, data sources and collection,\ndata synthesis, reporting, and decision-making and action\n\n## 🔗 Dedicated page\nCf. [SOC metrics (KPI/SLA)](https://github.com/cyb3rxp/awesome-soc/blob/main/metrics-kpi.md)\n\n\n\n# HR and training\n\n## MITRE reference\n* [11 strategies for a world-class SOC](https://github.com/cyb3rxp/awesome-soc/blob/main/11-strategies-of-a-world-class-cybersecurity-operations-center.pdf), Strategy 4: Hire AND Grow Quality Staff, pages 101-124\n\u003e Create an environment to attract the right people and encourage them to stay through career\nprogression opportunities and great culture and operating environment. Plan for turnover\nand build a pipeline to hire. Consider how many personnel are needed for the different SOC\nfunctions.\n\n## 🔗 Dedicated page\nCf. [HR and training](https://github.com/cyb3rxp/awesome-soc/blob/main/hr_training.md).\n\n\n# IT achitecture of a SOC\n\n## Have a single and centralized platform ('single console')\n\nAs per [NCSC website](https://www.ncsc.gov.uk/collection/building-a-security-operations-centre/detection/detection-practices#section_2):\n\u003e Indications of an attack will rarely be isolated events on a single system component or system. So, where possible, having a single platform where analysts have the ability to see and query log data from all of your onboarded systems is invaluable.\n\u003e Having access to the log data from multiple (or all) components, will enable analysts to look for evidence of attack across an estate and create detection use-cases that utilise a multitude of sources.\n\u003e By creating temporal (actions over a period of time) and spatial (actions across the estate) use-cases, an organisation is better prepared to address cyber security attacks that occur system wide.\n\n\n\n## Disconnect (as much as possible) SOC from monitored environment\n\nThe goal is to prevent an attacker from achieving lateral movement from a compromised monitored zone, to the SOC/CSIRT work zone.\n\n### Enclave: \n* Implement SOC enclave (with network isolation), as per MITRE paper drawing:\n![image](https://user-images.githubusercontent.com/16035152/186420265-4c0275b2-d70e-4fec-936c-712c1c4802a8.png)\n\n* only log collectors and WEF should be authorized to send data to the SOC/CSIRT enclave. Whenever possible, the SOC tools pull the data from the monitored environment, and not the contrary;\n\n* on top of a SOC enclave, implement at least a [level 2 of network segmentation](https://github.com/sergiomarotco/Network-segmentation-cheat-sheet#level-2-of-network-segmentation-adoption-of-basic-security-practices);\n\nSOC’s assets should be part of a separate [restricted AD forest](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/forest-design-models ), to allow AD isolation with the rest of the monitored AD domains. \n\n\n### Endpoints hardening:\n\n* SOC/CSIRT's endpoints should be hardened with relevant guidelines;\n   * My recommendations: [CIS benchmarks](https://www.cisecurity.org/cis-benchmarks/), [Microsoft Security Compliance Toolkit](https://www.microsoft.com/en-us/download/details.aspx?id=55319)\n\n\n# To go further\n\n## 📚 **Must Read**\n*Essential resources to build, run, and mature your SOC/CSIRT.*\n\n###  **Frameworks \u0026 Methodologies**\n- [MITRE, 11 strategies for a world-class SOC](11-strategies-of-a-world-class-cybersecurity-operations-center.pdf) *(PDF included in the repository)* – Comprehensive MITRE guide to building a high-performance SOC.\n- [Microsoft, SOC/IR hierarchy of needs](https://download.microsoft.com/download/E/6/2/E62530BF-47CC-4527-88BA-F13DF5294A65/HierarchyofCybersecurityNeeds.pdf) – Framework for SOC/IR maturity.\n- [Hunt.io, PEAK threat hunting framework](https://hunt.io/glossary/peak-threat-hunting-framework) – Framework for advanced threat hunting.\n- [PwnDefend, AD post-compromise checklist](https://www.pwndefend.com/2021/09/15/post-compromise-active-directory-checklist/) – Checklist for Active Directory compromise assessment.\n- [ANSSI (FR), EBIOS RM methodology](https://messervices.cyber.gouv.fr/guides/en-ebios-risk-manager-method) – French risk management methodology.\n- [GMU, Improving Social Maturity of Cybersecurity Incident Response Teams](https://edu.anarcho-copy.org/Against%20Security%20-%20Self%20Security/GMU_Cybersecurity_Incident_Response_Team_social_maturity_handbook.pdf) – Research on CSIRT team dynamics.\n- [Expel, Reduce FP in a SOC](https://expel.com/cyberspeak/reduce-false-positives-in-soc-operations/) - Reduce FP in a SOC.\n\n###  **Roles \u0026 Responsibilities**\n- [CISA, Cyber Defense Incident Responder role](https://www.cisa.gov/careers/work-rolescyber-defense-incident-responder) – Role definition and responsibilities for incident responders.\n\n###  **Threat Intelligence**\n- [MalAPI, list of Windows API and their potential use in offensive security](https://malapi.io/) – Windows API references for offensive/defensive security.\n- [FireEye, OpenIOC format](https://cloud.google.com/blog/topics/threat-intelligence/openioc-basics/?hl=en) – Open standard for sharing threat intelligence.\n- [Herman Slatman, Awesome Threat Intel](https://github.com/hslatman/awesome-threat-intelligence) – Curated list of threat intelligence resources.\n\n### **Compliance \u0026 Regulations**\n- [ENISA, Cybersecurity certificates](https://certification.enisa.europa.eu/certificates_en) – List of trusted cybersecurity service providers in the EU.\n\n### **Tools \u0026 Architectures**\n- [SentinelOne, EPP vs. EDR: Understanding the Differences](https://www.sentinelone.com/cybersecurity-101/endpoint-security/epp-vs-edr/) – Explanation of endpoint security technologies.\n- [Wavestone, Security bastion (PAM) and Active Directory tiering model](https://www.riskinsight-wavestone.com/en/2022/10/security-bastion-pam-and-active-directory-tiering-mode-how-to-reconcile-the-two-paradigms/) – How to reconcile PAM and AD tiering.\n- [Quest, Best practices for AD disaster recovery](https://blog.quest.com/active-directory-backup-strategies-you-need-today/) – AD backup best practices.\n- [Microsoft, Isolate Tier 0 assets with group policy](https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/initially-isolate-tier-0-assets-with-group-policy-to-start-administrative-tierin/1184934) – Guide to isolate Tier 0 assets.\n- [Gartner, Market guide for NDR](https://www.gartner.com/en/documents/4016572) – Market analysis of Network Detection and Response solutions.\n- [RecordedFuture](https://www.recordedfuture.com/threat-intelligence-101/tools-and-technologies/osint-tools) - Role of OSINT tools, brief history, and how to use these popular tools to deliver crucial intelligence insights.\n- [MDRProviders.io, comparison of managed detection and response providers](https://www.mdrproviders.io/) – Comparison of MDR providers by pricing, SLA, and breach warranty.\n\n###  **Use Cases \u0026 Implementations**\n- [Microsoft, Windows 10 and Windows Server 2016 security auditing and monitoring reference](https://www.microsoft.com/en-us/download/details.aspx?id=52630) – Auditing and monitoring guide for Windows.\n- [Medium, Wazuh at the heart of a SOC architecture for public/critical infrastructures](https://medium.com/@wazuh/wazuh-at-the-heart-of-a-soc-architecture-for-public-critical-infrastructures-1234567890) – Use case for Wazuh in SOC architectures.\n- [CyberVigilance, Mitre Engenuity Evaluations 2022 review](https://www.cybervigilance.uk/insights/2022-mitre-att-ck-engenuity-results) – Review of MITRE Engenuity evaluations.\n\n## 📖 **Nice to Read**\n*Additional resources to expand your knowledge.*\n\n### **Standards \u0026 Controls**\n- [NIST, SP800-53 rev5 (Security and Privacy Controls)](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final) – Security and privacy controls for information systems.\n- [CIS, Business Impact Analysis tool](https://www.cisecurity.org/cis-securesuite/business-impact-analysis-tool) – Guide for assessing business impact of cyber incidents.\n- [RFC2350 (CERT description)](https://tools.ietf.org/html/rfc2350) – Framework for describing a CERT.\n- [SOC CMM, SOCTOM](https://soc-cmm.com/soc-tom/) – SOC maturity model and tool.\n- [PTES](http://www.pentest-standard.org/index.php/PTES_Technical_Guidelines) – Penetration Testing Execution Standard.\n- [OWASP, WSTG](https://owasp.org/www-project-web-security-testing-guide/) – Web Security Testing Guide.\n- [Threat Hunting Framework](https://hunt.io/glossary/tahiti-threat-hunting-framework) - TaHiTI threat hunting framework.\n- [RecordedFuture, Threat Hunting](https://www.recordedfuture.com/blog/cyber-threat-hunting) - Using Threat Intelligence to master modern Threat Hunting.\n- EU, [TIBER purple teaming best practices](https://www.ecb.europa.eu/pub/pdf/annex/ecb.tiber_eu_purple_best_practices_2025.en.pdf)\n\n### **Cloud \u0026 Platforms**\n- [Amazon, AWS Security Fundamentals](https://aws.amazon.com/training/digital/aws-security-fundamentals/) – AWS security best practices.\n- [Microsoft, PAW Microsoft](https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/privileged-access-workstations) – Privileged Access Workstation (PAW) guidance.\n- [Elastic, BEATS agents](https://www.elastic.co/beats/)** – Lightweight agents for data collection.\n\n### **Incident Response**\n- [Incident Response \u0026 Computer Forensics, 3rd ed](https://www.amazon.com/Incident-Response-Computer-Forensics-Third/dp/007180131X) – Book on incident response and forensics.\n- [Austin Songer, Incident playbook](https://github.com/AustinSonger/Incident-Playbook) – Collection of incident response playbooks.\n- [CISA, Cybersecurity incident and vulnerability response playbooks](https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf) – Ready-to-use playbooks for incident response.\n\n### **SOC Tools \u0026 Architectures**\n- [Reprise99, Microsoft Sentinel queries](https://github.com/Reprise99/Sentinel-Queries) – KQL queries for Microsoft Sentinel.\n- [MyFaberSecurity, MS Sentinel architecture and recommendations for MSSP](https://myfabersecurity.com/2023/03/31/sentinel-poc-architecture-and-recommendations-for-mssps-part-1/) – Architecture and best practices for Microsoft Sentinel.\n- [Microsoft, Custom data ingestion and transformation in Microsoft Sentinel](https://learn.microsoft.com/en-us/azure/sentinel/data-transformation) – Scenarios for data collection in Microsoft Sentinel.\n\n### **Benchmarks \u0026 Surveys**\n- [SANS SOC survey 2022](https://www.sans.org/reading-room/whitepapers/analyst/2022-sans-soc-survey/) – Results of the 2022 SANS SOC survey.\n- [Gartner, PAM Magic Quadrant reprint](https://www.gartner.com/en/documents/4016568) – Market analysis of Privileged Access Management solutions.\n- [BitDefender, Analyzing MITRE ATT\u0026CK evaluations 2024](https://www.bitdefender.com/en-za/business/campaign/forrester-analysis-2024-mitre-engenuity#form) – Analysis of MITRE ATT\u0026CK evaluations.\n\n### **Miscellaneous Resources**\n- [Microsoft, command line reference](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/windows-commands) – Windows command-line reference.\n- [CyberFlooD SwitchToOpen](https://github.com/CyberFlooD/SwitchToOpen) – Guide to switch from proprietary to open-source security tools.\n- [CNIL, GDPR implications](https://www.cnil.fr/sites/cnil/files/2025-06/cybersecurity-economics-gdpr.pdf) – Economics implications of GDPR.\n- [CNIL, 2025 report](https://www.cnil.fr/en/annual-report-2025) - French CNIL's report for 2025.\n- [Sekoia, What is XDR?](https://www.sekoia.com/glossary/xdr) – Explanation of Extended Detection and Response (XDR).\n- [Microsoft, Licensing maps](https://m365maps.com/) – Licensing comparison for Microsoft Defender and Modern Work plans.\n- [SANS cheat sheets](https://www.sans.org/blog/the-ultimate-list-of-sans-cheat-sheets) - Ultimate list of (free) Cheat sheets.\n- [ENISA, Secure by design and default](https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook).\n\n\n\n## SOC sensors, nice to have\n* **Deceptive technology:**\n    * My recommendation: implement [AD decoy acounts](https://medium.com/securonix-tech-blog/detecting-ldap-enumeration-and-bloodhound-s-sharphound-collector-using-active-directory-decoys-dfc840f2f644) and [AD DNS canary](https://www.protect.airbus.com/blog/active-directory-a-canary-under-your-hat/)\n* WAF for internet-facing websites/apps:\n  * My recommendations:\n     * FOSS: [Crowdsec WAF](https://www.crowdsec.net/solutions/application-security), [Bunkerweb](https://github.com/bunkerity/bunkerweb?tab=readme-ov-file=)\n     * paid but good price: [CloudFlare](https://www.cloudflare.com/plans/)\n* MDM:\n  * My recommendation: [Microsoft Intune](https://docs.microsoft.com/en-us/mem/intune/fundamentals/what-is-intune)\n* (full-featured) Honeypot:\n  * My recommendation: [Canary.tools](https://canary.tools/)\n  * Or, have a look at [Awesome honeypots Git](https://github.com/paralax/awesome-honeypots)\n* Phishing and brand infringement protection (domain names):\n  * My recommendation: [PhishLabs](https://www.phishlabs.com/), [Netcraft](https://www.netcraft.com/cybercrime/fraud-detection/)\n* NIDS:\n  * My recommendation: [Crowdsec](https://www.crowdsec.net/product/crowdsec-security-engine), [ftagent-lite](https://github.com/Flowtriq/ftagent-lite) for lightweight flow-based network monitoring and DDoS detection (sFlow/NetFlow/IPFIX, adaptive baseline anomaly detection)\n* NDR:\n  * My recommendation: [Gatewatcher](https://www.gatewatcher.com/en/our-solutions/trackwatch/)\n  * See [Gartner MAgic Quadrant for NDR](https://www.gatewatcher.com/en/resource/2026-gartner-magic-quadrant-for-network-detection-and-response/)\n* DLP:\n  * See [Gartner reviews and ratings](https://www.gartner.com/reviews/market/data-loss-prevention)\n* OT (industrial) NIDS:\n  * My recommendation: [Nozomi Guardian](https://www.nozominetworks.com/products/guardian/)\n* Network TAP:\n  * My recommendation: [Gigamon](https://www.gigamon.com/products/access-traffic/network-taps.html)\n* Mobile network security (2G/3G):\n  * My recommendation: Dust Mobile.\n\n\n## Harden SOC/CSIRT environment\n* Implement hardening measures on SOC workstations, servers, and IT services that are used (if possible), e.g.:\n   * CIS [Benchmarks](https://www.cisecurity.org/);\n   * Microsoft [Security Compliance Toolkit](https://www.microsoft.com/en-us/download/details.aspx?id=55319);\n   * NIST, [SP800-63B: Digital Identity Guidelines](https://pages.nist.gov/800-63-4/sp800-63b.html)\n* Put the SOC assets in a separate AD forest, as [forest is the AD security boundary](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/gathering-information-about-your-active-directory-deployment), for isolation purposes, in case of a global enterprise's IT compromise\n* Create/provide a disaster recovery plan for the SOC assets and resources.\n* Implement admin bastions and silo to administrate the SOC env (equipments, servers, endpoints):\n  * My advice: consider the SOC environment as to be administrated by **Tier 1**, if possible with a dedicated admin bastion. Here is a generic drawing from Wavestone's article (see Must read references): ![image](https://user-images.githubusercontent.com/16035152/202517740-812091b6-ff31-49cd-941e-3f6e4b4d140c.png)\n  * Recommended technology choices: [Wallix PAM](https://www.wallix.com/privileged-access-management/)\n  * Implement a [level 3 of network segmentation](https://github.com/sergiomarotco/Network-segmentation-cheat-sheet#level-3-of-network-segmentation-high-adoption-of-security-practices)\n  * You may want to use throwable machines (virtual machines) for incident response or specific artefacts analysis. Here are my recommendations:\n    * [Microsoft Developer virtual machines](https://developer.microsoft.com/en-us/windows/downloads/virtual-machines/);\n    * Windows 11 [clean-up script](https://github.com/simeononsecurity/Windows-Optimize-Harden-Debloat);\n    * Windows 11 [hardening tool](https://apps.microsoft.com/detail/9p7ggfl7dx57?hl=en-US\u0026gl=US)\n    * If needed, [Flare-VM](https://github.com/mandiant/flare-vm) framework to automate security tools installation on analysts workstations;\n\n\n# Appendix\n\n## License\n[CC-BY-SA](https://en.wikipedia.org/wiki/Creative_Commons_license)\n\n## Special thanks\nYann F., Wojtek S., Nicolas R., Clément G., Alexandre C., Jean B., Frédérique B., Pierre d'H., Julien C., Hamdi C., Fabien L., Michel de C., Gilles B., Olivier R., Jean-François L., Fabrice M., Pascal R., Florian S., Maxime P., Pascal L., Jérémy d'A., Olivier C. x2, David G., Guillaume D., Patrick C., Lesley K., Gérald G., Jean-Baptiste V., Antoine C., David Q., Philippe M., ...\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/cyb3rxp%2Fawesome-soc/projects"}