ilyasoo05/playbook-soar-automatise
GitHub: ilyasoo05/playbook-soar-automatise
Stars: 0 | Forks: 0
# 🛡️ Playbook SOAR Automatisé
[](LICENSE)
[](https://wazuh.com)
[](https://thehive-project.org)
[](https://shuffler.io)
Automatisation de la détection et réponse aux incidents de sécurité via **Wazuh → Shuffle → TheHive**.
## 🏗️ Architecture
Wazuh (SIEM) → Shuffle (SOAR) → TheHive (SIRP)
## 🚀 Quick Start
bash scripts/install-docker.sh
bash scripts/deploy-thehive.sh
bash scripts/deploy-shuffle.sh
bash scripts/install-wazuh.sh
## 🧪 Tests
bash scripts/test-ssh-bruteforce.sh
bash scripts/test-nmap-scan.sh
## ✅ Results
| Test | Status |
|------|--------|
| SSH Brute Force Detection | ✅ Success |
| Nmap Port Scan Detection | ✅ Success |
| Automated Case Creation | ✅ Success |
| MTTR | ~2-3 seconds |
## 🛠️ Stack
| Component | Version | Role |
|-----------|---------|------|
| Wazuh | 4.14.5 | SIEM |
| Shuffle | Latest | SOAR |
| TheHive | 5.2.16 | SIRP |
| Docker | 29.5.0 | Containers |
| Ubuntu | 22.04 | OS |
## 👤 Author
**Ilyas**
## 📜 License
MIT License
EOF