1. What is SOAR?
SOAR (Security Orchestration, Automation and Response) is a cybersecurity platform that allows you to:
- Orchestrate security tools (SIEM, antivirus, firewall…)
- Automate security responses
- Respond quickly to incidents

Example:
When a phishing alert appears → SOAR can automatically:
- block the URL
- isolate the infected machine
- create an incident ticket
- notify the SOC analyst

2. Objectives of a SOAR Lab
This lab helps you learn how to:
- Understand the automated incident response cycle
- Connect multiple security tools together
- Build automated playbooks
- Reduce response time (MTTR)
- Simulate a real SOC environment

3. Tools Used in a SOAR Lab
SOAR Platform (choose one)
- Splunk SOAR
or
- Shuffle SOAR

SIEM (alert source)
- Splunk Enterprise

Case Management
- TheHive Project

Automation tools
- Cortex (malware analysis, IP reputation, hash lookup)

4. Main SOAR Interface Tabs and Their Purpose
Dashboard
- Global overview:
- active alerts
- open incidents
- executed playbooks

Alerts / Ingestion
- Incoming alerts from SIEM:
- phishing
- brute force
- malware detection

Entry point of SOC operations

Incidents
- Converts alerts into structured cases:
- severity level
- source IP
- affected machine
- status (open/closed)

Playbooks (core of SOAR)
Automated workflows such as:
1. Receive phishing alert
2. Analyze URL
3. Check IP reputation
4. Block malicious domain
5. Create SOC ticket

This is the automation brain of the SOC

Integrations
- Connects with:
- SIEM systems
- firewall
- antivirus
- external APIs (VirusTotal, etc.)

Cases / Tickets
- Full incident management:
- analyst assignment
- action timeline
- evidence collection

Logs / Audit
- Tracks everything:
- who did what
- when
- results

5. SOAR Lab Installation (Step-by-Step)

Step 1: Prepare the environment
Install:
- VirtualBox or VMware
- Ubuntu Server VM

Step 2: Install Docker
```bash
sudo apt update
sudo apt install docker.io -y
sudo systemctl start docker
sudo systemctl enable docker
```

Step 3: Install SOAR (Shuffle)
```bash
git clone https://github.com/frikky/Shuffle
cd Shuffle
docker compose up -d
```

Access:
http://localhost:3001

Step 4: Install SIEM (Splunk)
- Install Splunk Enterprise
- Open:
http://localhost:8000

Login:
- admin / password

Step 5: Install TheHive
```bash
docker run -d -p 9000:9000 thehiveproject/thehive
```

Access:
http://localhost:9000

6. Full Practical Scenario (Click-by-Click)

Case: Phishing Attack Detected

Step 1: Alert in Splunk
- Go to Search & Reporting
- Run query:
```bash
index=security phishing
```

Result:
- suspicious URL detected

Step 2: Send to SOAR
In Splunk:
- Click Alert Action
- Select: “Send to Shuffle SOAR”

Step 3: SOAR receives alert
In Shuffle:
- Go to Workflows
- New alert appears

Step 4: Run Playbook
Click:
“Run Workflow”

Automatic actions:
- URL analysis
- IP reputation check
- malware scanning

Step 5: SOAR Result
- Safe URL → ignore
- Malicious URL → action required

Step 6: Automated Response
If malicious:
- firewall blocks domain
- ticket created in TheHive
- SOC notification sent

Step 7: Incident in TheHive
New case contains:
- source IP
- URL
- threat level

Step 8: Closure
SOC analyst:
- validates action
- closes incident

7. Final Result of the Lab
You now have a system that can:
- detect attacks
- analyze them automatically
- block threats
- create SOC tickets
- notify analysts

All with minimal human intervention

Simple Conclusion
A SOAR is:
The automated brain of a modern SOC

It transforms:
- raw alerts
into
- intelligent automated responses



 

 

 

 



 

     

      

      
 

      

      

 


 

 

 

       

          

 

Copyright © All rights reserved.

 

     
* Cybersecurity Analyst
* SOC Analyst
* Security Operations Center
* Cloud Security
* DevSecOps
* Information Security
* Cybersecurity Engineer
* Threat Detection
* Incident Response
* SIEM Monitoring

---

# 🛡️ 2. Mots-clés SOC (très importants pour recrutement)

* SOC Analyst Tier 1
* SOC Analyst Tier 2
* Security Monitoring
* Log Analysis
* Security Alerts
* Threat Hunting
* Malware Analysis
* Phishing Detection
* Brute Force Detection
* Incident Investigation
* Security Events
* Blue Team

---

# ☁️ 3. Mots-clés Cloud Security

* Cloud Security Engineer
* AWS Security
* Azure Security
* Cloud Infrastructure Security
* Cloud Threat Detection
* Cloud Monitoring
* Identity and Access Management (IAM)
* Cloud Compliance
* Cloud Security Best Practices

---

# ⚙️ 4. Mots-clés DevSecOps

* DevSecOps Engineer
* Secure CI/CD Pipeline
* Security Automation
* Infrastructure as Code Security
* Docker Security
* Kubernetes Security
* Application Security
* Code Security
* SAST / DAST
* Continuous Security

---

# 🔬 5. Mots-clés techniques (très puissants SEO)

* Splunk
* ELK Stack (Elasticsearch, Logstash, Kibana)
* Microsoft Sentinel
* Wireshark
* Sysmon
* Linux Security
* Windows Security Logs
* Network Security
* Firewall Logs
* IDS / IPS

---

# 🚀 6. Mots-clés “portfolio / recrutement”

👉 Très important pour être trouvé par RH

* Cybersecurity Portfolio
* SOC Analyst Portfolio
* Cybersecurity Projects
* Cybersecurity Labs
* Security Use Cases
* Threat Detection Lab
* Cybersecurity Skills
* Entry Level Cybersecurity
* Junior Cybersecurity Analyst

---

# 📈 7. Mots-clés SEO longue traîne (ULTRA PUISSANT)

👉 Ceux-là font la différence 🔥

* Cybersecurity analyst portfolio website
* SOC analyst projects and labs
* How to detect cyber attacks using SIEM
* Cybersecurity incident response examples
* Cloud security best practices for beginners
* DevSecOps security pipeline example
* SIEM log analysis tutorial
* Threat detection use cases

---

# 🧠 STRATÉGIE SEO (très important)

## 📌 Où mettre ces mots-clés :

* Page d’accueil (titre + description)
* Page “About”
* Page “Labs”
* Titres H1 / H2 / H3
* Meta description
* URL des pages

---

# 🏆 EXEMPLE DE TITRE SEO (à utiliser)

👉
**Cybersecurity Analyst Portfolio | SOC, Cloud Security & DevSecOps Projects**

---

# 🏆 EXEMPLE META DESCRIPTION

👉
**Cybersecurity Analyst portfolio with hands-on labs in SOC monitoring, SIEM, Cloud Security and DevSecOps. Available for hiring.**

---
 

Manager DSI (secteur bancaire)

🎯 Mots-clés principau

# 🏦 🔥 1. Mots-clés Manager DSI (secteur bancaire)

## 🎯 Mots-clés principaux

* IT Manager
* IT Director
* Head of IT
* IT Governance
* Information Systems Management
* Digital Transformation
* IT Strategy
* Enterprise IT

---

## 🏦 Spécifique BANQUE (très puissant)

* Banking IT Systems
* Core Banking Systems
* Financial Information Systems
* Banking Cybersecurity
* Risk Management Banking
* IT Compliance Banking
* Data Protection Banking
* Financial Security

---

## ⚖️ Gouvernance & conformité

* IT Governance Framework
* COBIT
* ITIL
* Risk Assessment
* Business Continuity Plan (BCP)
* Disaster Recovery Plan (DRP)
* Regulatory Compliance

---

## 📊 Management & pilotage

* IT Project Management
* Team Leadership IT
* IT Operations Management
* KPI IT Performance
* IT Service Management (ITSM)
* Strategic IT Planning

---

# 🏥 🛡️ 2. Mots-clés RSSI (hôpital / santé)

## 🎯 Mots-clés principaux

* Chief Information Security Officer (CISO)
* Information Security Manager
* Cybersecurity Governance
* Security Risk Management
* Security Policies

---

## 🏥 Spécifique SANTÉ (très important)

* Healthcare Cybersecurity
* Hospital Information Systems (HIS)
* Patient Data Protection
* Medical Data Security
* Health IT Security
* Electronic Health Records (EHR) Security

---

## 🔐 Sécurité & conformité

* ISO 27001
* NIST Cybersecurity Framework
* GDPR Compliance
* Data Privacy
* Access Control
* Identity Management

---

## 🚨 Gestion des incidents

* Incident Response Management
* Security Operations Management
* Cyber Risk Assessment
* Vulnerability Management
* Threat Intelligence

---

# 🚀 🧠 3. Mots-clés hybrides (TRÈS PUISSANTS 🔥)

👉 Ceux-là font le lien entre ton profil actuel et ton évolution :

* Cybersecurity Leadership
* IT Security Strategy
* Enterprise Security Architecture
* Security Governance
* IT Risk Management
* Digital Security Transformation
* Cloud Security Governance