MSSP SOC Build on Open Source
A multi-tenant SOC for new MSSPs on Wazuh, DFIR-IRIS, OpenCTI and n8n, built on your own server in 5 weeks with AI triage and client reports included.
How an alert becomes a case
- Wazuh alert: Level 7 and above, per client
- Dedupe: Same rule and host within 15 min
- Enrich: IPs, domains and hashes against OpenCTI first, then VirusTotal and AbuseIPDB
- Verdict: Local AI on Ollama plus scoring: true positive, false positive or review
- IRIS case: Tagged to the client, evidence attached
- Analyst: Works the case instead of the queue
The stack
Detect
- Wazuh (SIEM and XDR): Agents on every endpoint and one manager per client, so a rule change for one client never touches another
- Graylog (Network logs): A collector at the client site parses firewall and switch syslog locally and forwards only the security events
Investigate
- DFIR-IRIS (Case management): Owner, timeline and evidence for every case, unlimited analyst accounts, and one customer space per client
- OpenCTI (Threat intelligence): Pulls MITRE ATT&CK, CVE, AlienVault OTX, URLhaus and ThreatFox on a schedule and answers lookups locally, with no rate limits
- VirusTotal + AbuseIPDB (IP and hash reputation): The fallback when OpenCTI has no answer for an IP address, domain or file hash
Automate
- n8n (Automation engine): Runs triage, enrichment, client reports and rule tuning on a schedule or on every alert
- Ollama (Local AI model): Runs the AI model behind triage verdicts on your own server, so alert data never goes to a cloud AI service
- NeetroX automations (Triage, reports, tuning): Five production workflows deployed into n8n and adapted to your naming. Listed one by one below
Run and protect
- Proxmox VE (Your server): Everything runs on your own bare-metal host. NeetroX hosts nothing and keeps no copy of client data
- WireGuard (Analyst access): Consoles are reached over VPN only. One machine faces the internet, and adding a client changes nothing else
- NetBird (Zero-trust access): A WireGuard mesh with SSO and per-user access rules, for analysts and client-site collectors, with no inbound ports to open
- Proxmox Backup Server (Off-host backups): Nightly deduplicated backups to a separate machine, with a full restore tested on your hardware before handover
- Git (Config as code): Rules, configs, retention policies, workflow exports and runbooks versioned in your private repo
Five NeetroX automations included
- SOC Analyst L1: Triages every Wazuh alert: dedupes, enriches, reaches a verdict and opens an IRIS case for the ones that matter. It is what lets a team of two or three run the estate
- Wazuh Rule Tuner: Finds the noisiest rules and the false positives L1 keeps closing, tests each fix in a lab tenant, and deploys only after an analyst approves
- Monthly SIEM Report: One branded PDF per client per month: a technical version for your analysts and a summary for their management
- Weekly Vulnerability & Patch Report: The CVEs actually present on each client’s hosts, from Wazuh’s own data, ranked by severity and exposure
- Multi-Tenant Client Dashboard: One dashboard per client under your brand. Client A never sees client B
Multi-tenant from client one
- Wazuh manager: Client A Manager A, Client B Manager B
- Alert index: Client A alerts-clienta-*, Client B alerts-clientb-*
- Retention: Client A Set by A’s contract, Client B Set by B’s contract
- Case space: Client A IRIS customer A, Client B IRIS customer B
- Rule IDs: Client A 100000 to 100999, Client B 101000 to 101999
- Client portal: Client A Sees A only, Client B Sees B only
Five weeks from deposit to handover
- Week 1, Foundation: Host check, secure access, rebuild templates, private git repo
- Week 2, Detection: Wazuh for your first client, tenant roles, retention, a lab tenant for testing rules
- Week 3, Response: n8n, DFIR-IRIS, SOC Analyst L1, client dashboard, client-site collector
- Week 4, Intel and reporting: Rule Tuner, monthly and weekly reports, OpenCTI with its feeds
- Week 5, Handover: Off-host backups, a tested restore, the manual, runbooks and a handover session
What you get
- Design and build on your server
- The five NeetroX automations, adapted to your naming
- Lab tenant so rule changes are tested before a client sees them
- Off-host backups with a tested full restore
- Deployment manual, runbooks and a disaster-recovery plan
- A fixed add-a-client checklist
- Handover session with your team
- 30 days of post-delivery fixes
Not included: Hardware and backup storage, Commercial threat-intel feeds, Microsoft licences, On-site work
What you bring
- Server
- 30 CPU cores, 96 GB RAM (80 GB workable), about 2 TB of storage. A GPU is optional and speeds up the local AI
- Network
- One public IPv4 and a domain for the client dashboard
- Backups
- A second machine or a rented storage box, off the main host
- Access
- Root on the Proxmox host and a VPN or SSH route in
Common questions
- Who is this for?
- Teams starting an MSSP, or adding managed detection to an IT services business, who want a SOC they own instead of renting one per endpoint
- Do you host anything?
- No. Everything runs on your server and your data never leaves it. NeetroX reaches the platform over your VPN during the build
- Why DFIR-IRIS and not TheHive?
- TheHive 5 Community is capped at one organisation and two users, and TheHive 4 has been unmaintained since December 2022. IRIS is free, maintained, has unlimited analyst accounts and a customer object for each client
- How many clients can one server take?
- Two more clients of about 100 endpoints each fit with no change to the design. Past that, disk is the first purchase, then RAM, well before a second server
- Who triages alerts after handover?
- Your analysts. SOC Analyst L1 does the first pass on every alert, so they work cases that survived triage. The optional Managed plan keeps the automation running; incident response stays with your team
- How is the price set?
- Fixed for the agreed scope, quoted after a 15-minute call once we know your endpoint count and hardware. 50% at signature and 50% at acceptance