Austin Hsieh

SOC Monitoring Lab · HYC 412

soc-monitoring.dev

Security Operations Architecture SOC · XDR · AI · Cloud

A practical security operations lab focused on monitoring, alerting, and evolving toward modern enterprise architecture including XDR, AI-assisted analysis, governance, and hybrid cloud design.

View Project Architecture Contact

Architecture Overview

Log Ingestion

Wazuh, Syslog, and API-based ingestion pipeline.

SOC Core

FastAPI backend with PostgreSQL and rule-based alert engine.

Detection & Response

SIEM concepts extended toward XDR integration.

AI & Governance

AI-assisted analysis and enterprise governance design.

Key Capabilities

Alert Pipeline

Structured alert generation from log data.

Query-based Analysis

Filtering and investigation workflow.

Future-ready Architecture

Designed for AI, XDR, and cloud integration.

Demo Preview

A visual concept of the SOC console experience, focused on alert visibility, log analysis, and investigation workflow.

HYC 412 Console

Logs Ingested

12,480

last 24 hours

Alerts

36

severity-based detection

Rules Active

8

pipeline monitoring

Recent Alerts

Live View
Alert
Severity
Source
Time
Suspicious login pattern
high
wazuh
2026-03-21 10:42
Repeated authentication failure
medium
syslog
2026-03-21 09:58
Malware indicator detected
critical
siem
2026-03-21 08:21

Use Case Scenario

Suspicious Login Detection

Ingest authentication logs via Wazuh, normalize events, and trigger alerts when abnormal login patterns are detected.

Alert Investigation Workflow

Analysts query alerts using filter-based APIs to identify source, severity, and event patterns for rapid triage.

Future AI Integration

Extend alerts with AI-generated summaries and classification to reduce investigation time and improve response accuracy.

Positioning

Security Engineer focused on SOC monitoring, cloud architecture, and AI-driven security operations. Bridging traditional infrastructure experience with modern security and data-driven approaches.

Contact

For collaboration, technical discussion, or opportunities, feel free to reach out.

austin@soc-monitoring.dev