ilyasoo05/playbook-soar-automatise
GitHub: ilyasoo05/playbook-soar-automatise
基于 Wazuh-Shuffle-TheHive 三层架构的开源自动化安全事件响应 Playbook,实现从威胁检测到案件创建的全流程自动化。
Stars: 0 | Forks: 0
# 🛡️ 自动化 SOAR Playbook
[](LICENSE)
[](https://wazuh.com)
[](https://thehive-project.org)
[](https://shuffler.io)
通过 **Wazuh → Shuffle → TheHive** 自动化检测和响应安全事件。
## 🏗️ 架构
Wazuh (SIEM) → Shuffle (SOAR) → TheHive (SIRP)
## 🚀 快速开始
```
bash scripts/install-docker.sh
bash scripts/deploy-thehive.sh
bash scripts/deploy-shuffle.sh
bash scripts/install-wazuh.sh
```
## 🧪 测试
```
bash scripts/test-ssh-bruteforce.sh
bash scripts/test-nmap-scan.sh
```
## ✅ 结果
| 测试 | 状态 |
|------|--------|
| SSH 暴力破解检测 | ✅ 成功 |
| Nmap 端口扫描检测 | ✅ 成功 |
| 自动创建案例 | ✅ 成功 |
| MTTR | ~2-3 秒 |
## 🛠️ 技术栈
| 组件 | 版本 | 角色 |
|-----------|---------|------|
| Wazuh | 4.14.5 | SIEM |
| Shuffle | Latest | SOAR |
| TheHive | 5.2.16 | SIRP |
| Docker | 29.5.0 | Containers |
| Ubuntu | 22.04 | OS |
## 👤 作者
**Ilyas**
## 📜 许可证
MIT License
EOF
标签:Docker, FTP漏洞扫描, SOAR, 安全编排, 安全运营, 安全防御评估, 应用安全, 扫描框架, 插件系统, 自动化响应, 请求拦截