SOC Implementation for Cybersecurity Incident Handling Optimization

Authors

  • I Gede Adnyana Adnyana Institut Bisnis dan Teknologi Indonesia, Denpasar, Indonesia
  • I Nyoman Buda Hartawan Hartawan Institut Bisnis dan Teknologi Indonesia, Denpasar, Indonesia
  • I Nyoman Arnawan Institut Bisnis dan Teknologi Indonesia, Denpasar, Indonesia
  • Mahesa Rama Aditya Institut Bisnis dan Teknologi Indonesia, Denpasar, Indonesia

DOI:

https://doi.org/10.58982/kjvrk872

Keywords:

Security Operations Center; Wazuh; SIEM; n8n; Telegram

Abstract

Cybersecurity incidents continue to increase in complexity and impact, requiring institutions to improve their monitoring and response capabilities. This study implements a simple Security Operations Center (SOC) workflow to support cybersecurity incident handling through endpoint monitoring, alert generation, workflow automation, and real-time notification. The system integrates Wazuh as a Security Information and Event Management platform, Wazuh Agent as an endpoint log collector, n8n as a workflow automation tool, and Telegram as a notification channel. The implementation was carried out by deploying the required services using Docker, registering monitored endpoints through Wazuh Agent, configuring Wazuh alerts, forwarding alerts to n8n through webhook integration, parsing important alert fields, and sending structured notifications to administrators through Telegram. The system was evaluated through several test scenarios, including agent connectivity, failed SSH login detection, malware detection, Wazuh-to-n8n alert delivery, alert parsing, and Telegram notification delivery. The results show that the implemented SOC workflow successfully receives endpoint logs, generates security alerts, processes alert data automatically, and sends real-time notifications to administrators. This implementation demonstrates that open-source tools can be integrated to build a practical SOC workflow for improving initial cybersecurity incident awareness and response.

References

[1] M. P. Aji, “Sistem Keamanan Siber dan Kedaulatan Data di Indonesia dalam Perspektif Ekonomi Politik (Studi Kasus Perlindungan Data Pribadi) [Cyber Security System and Data Sovereignty in Indonesia in Political Economic Perspective],” J. Polit. Din. Masal. Polit. Dalam Negeri Dan Hub. Int., vol. 13, no. 2, pp. 222–238, Jan. 2023, doi: 10.22212/jp.v13i2.3299.

[2] P. Prabaswari, M. Alfikri, and I. Ahmad, “Evaluasi Implementasi Kebijakan Pembentukan Tim Tanggap Insiden Siber pada Sektor Pemerintah,” Matra Pembaruan, vol. 6, no. 1, pp. 1–14, May 2022, doi: 10.21787/mp.6.1.2022.1-14.

[3] F. H. Sigiro, A. J. S. Runturambi, and B. Widiawan, “Collaborative Sharing Intelijen Ancaman Pada Komunitas Csirt Dalam Memperkuat Keamanan Siber Nasional,” Syntax Lit. J. Ilm. Indones., vol. 7, no. 9, pp. 15212–15229, Dec. 2023, doi: 10.36418/syntax-literate.v7i9.14245.

[4] I. Elan Maulani and A. Faisal Umam, “Evaluasi Efektivitas Sistem Deteksi Intrusi Dalam Menjamin Keamanan Jaringan,” J. Sos. Teknol., vol. 3, no. 8, pp. 662–667, Aug. 2023, doi: 10.59188/jurnalsostech.v3i8.907.

[5] I. G. Adnyana, A. M. Dirgayusari, and K. J. Atmaja, “Data Visualization for Building a Cyber Attack Monitoring Dashboard Based on Honeypot,” sinkron, vol. 8, no. 4, pp. 2510–2518, Oct. 2024, doi: 10.33395/sinkron.v8i4.14144.

[6] I. G. Adnyana, P. Sugiartawan, and I. N. B. Hartawan, “Hyperparameter Optimization Techniques for CNN-Based Cyber Security Attack Classification,” IJCCS Indones. J. Comput. Cybern. Syst., vol. 18, no. 3, Jul. 2024, doi: 10.22146/ijccs.98427.

[7] Y. B. Abushark et al., “Cyber Security Analysis and Evaluation for Intrusion Detection Systems,” Comput. Mater. Contin., vol. 72, no. 1, pp. 1765–1783, 2022, doi: 10.32604/cmc.2022.025604.

[8] A. Singh, J. Prakash, G. Kumar, P. K. Jain, and L. S. Ambati, “Intrusion Detection System: A Comparative Study of Machine Learning-Based IDS,” J. Database Manag., vol. 35, no. 1, pp. 1–25, Feb. 2024, doi: 10.4018/JDM.338276.

[9] X. Yang, J. Yuan, H. Yang, Y. Kong, H. Zhang, and J. Zhao, “A Highly Interactive Honeypot-Based Approach to Network Threat Management,” Future Internet, vol. 15, no. 4, p. 127, Mar. 2023, doi: 10.3390/fi15040127.

[10] E. Seid, O. Popov, and F. Blix, “Towards Security Attack Event Monitoring for Cyber Physical-Systems:,” in Proceedings of the 9th International Conference on Information Systems Security and Privacy, Lisbon, Portugal: SCITEPRESS - Science and Technology Publications, 2023, pp. 722–732. doi: 10.5220/0011803400003405.

[11] H. Hanafi, A. Pranolo, Y. Mao, T. Hariguna, L. Hernandez, and N. F. Kurniawan, “IDSX-Attention: Intrusion detection system (IDS) based hybrid MADE-SDAE and LSTM-Attention mechanism,” Int. J. Adv. Intell. Inform., vol. 9, no. 1, p. 121, Mar. 2023, doi: 10.26555/ijain.v9i1.942.

[12] A. Shafiyyah, G. F. Nama, and R. A. Pradipta, “Implementasi Wazuh Menggunakan Metode PPDIOO di Sistem Keamanan Jaringan PSDKU Universitas Lampung Waykanan Sebagai Deteksi dan Respon Serangan Siber,” J. Inform. Dan Tek. Elektro Terap., vol. 12, no. 2, Apr. 2024, doi: 10.23960/jitet.v12i2.4074.

[13] M. R. T. Hidayat, N. Widiyasono, and R. Gunawan, “Optimasi Deteksi Malware Pada Siem Wazuh Melalui Integrasi Cyber Threat Intelligence dengan MISP dan DFIR-IRIS,” J. Inform. Dan Tek. Elektro Terap., vol. 13, no. 1, Jan. 2025, doi: 10.23960/jitet.v13i1.5686.

[14] I. Taqafi, Y. Maleh, and K. Ouazzane, “A Maturity Capability Framework for Security Operation Center,” EDPACS, vol. 67, no. 3, pp. 21–38, Mar. 2023, doi: 10.1080/07366981.2023.2159047.

[15] S. Waelchli and Y. Walter, “Reducing the risk of social engineering attacks using SOAR measures in a real world environment: A case study,” Comput. Secur., vol. 148, p. 104137, Jan. 2025, doi: 10.1016/j.cose.2024.104137.

[16] A. O. Aljahdali and R. Alsulami, “Streamlining Threat Response and Automating Critical Use Cases with Security Orchestration, Automation and Response (SOAR),” J. Digit. Secur. Forensics, vol. 2, no. 1, pp. 36–57, May 2025, doi: 10.29121/digisecforensics.v2.i1.2025.45.

[17] T. Purnama, Y. Muhyidin, and D. Singasatia, “Implementasi Intrusion Detection System (IDS) Snort Sebagai Sistem Keamanan Menggunakan Whatsapp dan Telegram sebagai Media Notifikasi,” J. Teknol. Inf. DAN Komun., vol. 14, no. 2, pp. 358–369, Sep. 2023, doi: 10.51903/jtikp.v14i2.726.

[18] H. S. Lallie, A. Thompson, E. Titis, and P. Stephens, “Analysing Cyber Attacks and Cyber Security Vulnerabilities in the University Sector,” Computers, vol. 14, no. 2, p. 49, Feb. 2025, doi: 10.3390/computers14020049.

[19] M. M. A. Parambil et al., “Integrating AI-based and conventional cybersecurity measures into online higher education settings: Challenges, opportunities, and prospects,” Comput. Educ. Artif. Intell., vol. 7, p. 100327, Dec. 2024, doi: 10.1016/j.caeai.2024.100327.

[20] J. Forsberg and T. Frantti, “Technical Performance Metrics of a Security Operations Center,” Comput. Secur., vol. 135, p. 103529, Dec. 2023, doi: 10.1016/j.cose.2023.103529.

Downloads

Published

2026-07-24

How to Cite

SOC Implementation for Cybersecurity Incident Handling Optimization. (2026). Krisnadana Journal, 5(3), 689-699. https://doi.org/10.58982/kjvrk872

Similar Articles

You may also start an advanced similarity search for this article.