SOC Register — Defensive Security
A security operations management application for tracking SOC activities, incidents, users, roles, and operational records.
Built with TypeScript, Next.js, PostgreSQL, RBAC
Defensive Security
Integrations for threat intelligence APIs — indicators of compromise, reputation checking, and SIEM enrichment.
| Category | Defensive Security |
|---|---|
| Technologies | Python, MISP, IBM QRadar, REST APIs |
| Links | source |
Integration work that connects threat intelligence sources to the places analysts actually look: pulling indicators of compromise, checking reputations, and enriching SIEM events so triage starts with context instead of raw addresses.
Threat intelligence is only useful at the moment of triage. When reputation data lives in separate portals, analysts either waste time pivoting between tabs or skip the check entirely.
Glue integrations that bring IOC feeds and reputation lookups into the SIEM pipeline, so events arrive pre-enriched with the context needed to make a fast, correct call.
Enrichment is a latency problem: intelligence that arrives after the analyst has moved on might as well not exist.
Related projects
A security operations management application for tracking SOC activities, incidents, users, roles, and operational records.
Built with TypeScript, Next.js, PostgreSQL, RBAC
Python and Bash scripts for vulnerability scanning, threat intelligence, security monitoring, and repetitive security workflows.
Built with Python, Bash, REST APIs
An open-source JavaScript and TypeScript password strength and password policy validation library.
Built with TypeScript, JavaScript, npm