MSSP SOC Build on Open Source

A multi-tenant SOC for new MSSPs on Wazuh, DFIR-IRIS, OpenCTI and n8n, built on your own server in 5 weeks with AI triage and client reports included.

How an alert becomes a case

  1. Wazuh alert: Level 7 and above, per client
  2. Dedupe: Same rule and host within 15 min
  3. Enrich: IPs, domains and hashes against OpenCTI first, then VirusTotal and AbuseIPDB
  4. Verdict: Local AI on Ollama plus scoring: true positive, false positive or review
  5. IRIS case: Tagged to the client, evidence attached
  6. Analyst: Works the case instead of the queue

The stack

Detect

Investigate

Automate

Run and protect

Five NeetroX automations included

Multi-tenant from client one

Five weeks from deposit to handover

  1. Week 1, Foundation: Host check, secure access, rebuild templates, private git repo
  2. Week 2, Detection: Wazuh for your first client, tenant roles, retention, a lab tenant for testing rules
  3. Week 3, Response: n8n, DFIR-IRIS, SOC Analyst L1, client dashboard, client-site collector
  4. Week 4, Intel and reporting: Rule Tuner, monthly and weekly reports, OpenCTI with its feeds
  5. Week 5, Handover: Off-host backups, a tested restore, the manual, runbooks and a handover session

What you get

Not included: Hardware and backup storage, Commercial threat-intel feeds, Microsoft licences, On-site work

What you bring

Server
30 CPU cores, 96 GB RAM (80 GB workable), about 2 TB of storage. A GPU is optional and speeds up the local AI
Network
One public IPv4 and a domain for the client dashboard
Backups
A second machine or a rented storage box, off the main host
Access
Root on the Proxmox host and a VPN or SSH route in

Common questions

Who is this for?
Teams starting an MSSP, or adding managed detection to an IT services business, who want a SOC they own instead of renting one per endpoint
Do you host anything?
No. Everything runs on your server and your data never leaves it. NeetroX reaches the platform over your VPN during the build
Why DFIR-IRIS and not TheHive?
TheHive 5 Community is capped at one organisation and two users, and TheHive 4 has been unmaintained since December 2022. IRIS is free, maintained, has unlimited analyst accounts and a customer object for each client
How many clients can one server take?
Two more clients of about 100 endpoints each fit with no change to the design. Past that, disk is the first purchase, then RAM, well before a second server
Who triages alerts after handover?
Your analysts. SOC Analyst L1 does the first pass on every alert, so they work cases that survived triage. The optional Managed plan keeps the automation running; incident response stays with your team
How is the price set?
Fixed for the agreed scope, quoted after a 15-minute call once we know your endpoint count and hardware. 50% at signature and 50% at acceptance