Skip to content

socfortress/ASK-SOCFortress

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

26 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ASK SOCFortress Awesome

Your Open-Source SOC Assistant

MIT License LinkedIn your-own-soc-free-for-life-tier


Logo

ASK SOCFortress

Your Open-Source SOC Assistant
Sign Up Now »

Currently in Beta

Table of Contents
  1. Intro
  2. Install
  3. Configuration
  4. Running the Module

Intro

Welcome to Your Open-Source SOC Assistant, your go-to solution for improving your organization's security operations center (SOC). Built into our favorite Open-Source tools, ASK SOCFortress help analysts investigate alerts that pertain to IPs, domains, and file hashes. ASK SOCFortress streamlines and simplifies SOC investigations, saving time and improving accuracy.

Whether you're a security analyst or a member of a SOC team, Your Open-Source SOC Assistant can help you investigate alerts and provide technical assistance to enhance your security posutre. The module currently integrates with DFIR-IRIS (Shuffle coming soon) making it a valuable addition to any security operations workflow.

Our open-source project is constantly evolving, with new playbooks, features, and integrations. We welcome contributions and feedback from the community, so please feel free to get involved and help make ASK SOCFortress even better.

Get started today and see how ASK SOCFortress can take your security operations to the next level.

Procedure




Technical




Install

Currently, ASK SOCFortress can be ran as DFIR-IRIS Module.

Get started with DFIR-IRIS: Video Tutorial

The below steps assume you already have your own DFIR-IRIS application up and running.

  1. Fetch the ASK SOCFortress Repo
    git clone https://github.com/socfortress/ASK-SOCFortress
    cd ASK-SOCFortress
    
  2. Install the module
    ./buildnpush2iris.sh -a
    

Configuration

Once installed, configure the module to include:

  • API Key
  • Firewall Vendor

Register for an API Key

Current supported Firewall Vendors

  1. Navigate to Advanced -> Modules

Advanced -> Modules




  1. Add a new module

Add a new module




  1. Input the Module name: iris_asksocfortressbeta_module

Input Module




  1. Configure the module

Configure Module




Running the Module

To run the module select Case -> IOC and select the dropdown menu.

Beta currently supports IoC of type: ip, domain, md5, sha224, sha256, sha512

IoC




Run Module




Refresh the webpage within your browser.

Auto refresh is coming soon

View Report




Issues?

If you are experiencing issues, please contact us at [email protected]