SOC overview
Live event timeline, attack geo-map, KPIs: EPS, alerts/24h, MTTR, riskscore. Single pane of glass.
Not "security as a service", and not Excel full of open incidents. SIEM, EDR, NGFW/IPS/WAF, DLP, threat intel, MITRE ATT&CK coverage, IRP with auto-playbooks — one connected platform. One context, one war-room, one MTTR metric. Our SOC is on duty, or yours is.
Community OSS · Enterprise · Managed SOC 24×7
A SOC stitched together from 8 products means 8 invoices, 8 data models, 8 different APIs. Outsourced MSSP is a black box. We tried to take the best of both approaches.
Connected data model: SIEM alert → incident with killchain → playbook → action item → compliance control. Not 8 products with integrations, but one platform with categories. Operations · live SOC
Live event timeline, attack geo-map, KPIs: EPS, alerts/24h, MTTR, riskscore. Single pane of glass.
Chat with the on-duty SOC engineer + AI Atlas. Quick-actions: containment, isolation, blocklist push.
Killchain timeline with MITRE tags at each step. Alert → incident → post-mortem → action item, fully linked.
1.24M EPS · 90 days hot-storage · ECS format · ad-hoc query language. Saved hunts.
14 enterprise tactics. Coverage in %, hits over 30 days, hot-techniques. Mapping derived automatically from the rule engine.
Ready playbooks: ransomware, credential stuffing, BEC, supply-chain, web defacement. Launch from an incident in 1 click.
STIX 2.1 feed, MISP-compatible. IOC matching on streams. AI hunter agents: beaconing, DGA, LOLBin.
Zone-based, app-id, TLS decrypt optional. Auto rule generation from ML.
Suricata-style rules + our ML feed. Inline blocking, MITRE-mapped signatures.
OWASP Top 10 coverage, anti-bot, custom rules per site. Geo-blocking.
1,842 endpoints, process-tree analytics, behavior rules, isolation in 1 click.
Content classification (PII, code, secrets), DLP policies on endpoints and in traffic.
Continuous scan, CVE feed, exploit weather. Prioritization by asset criticality + KEV.
Auto-discovery: cloud, on-prem, endpoints. Inventory linked to incidents and compliance controls.
FZ-152 / FSTEC / PCI DSS / ISO 27001 / GOST. Failed controls show up as incidents, action items auto-generated.
Every detection rule is mapped to a technique. Here are 5 of 14 tactics as a preview, numbers are live coverage in %. Hot techniques are highlighted — there's real traffic on those over the last 30 days.
Banks, public sector, telecom. Compliance dashboards for FZ-152/FSTEC/PCI/GOST out of the box. Air-gapped install optional.
K8s/serverless workloads, OTel logs, CI/CD incidents. EDR agents for containers and VMs, eBPF telemetry.
No 24×7 staff on duty? The Managed SOC tier: our SOC stands watch, you get ready-to-act incidents in Slack.
On-prem servers + h3llo cloud + third-party providers. Universal SIEM collector + a single data model.
Community — the full platform up to 100K EPS. Enterprise — no limits and air-gapped. Managed SOC — our SOC is on duty 24×7, MTTD ≤ 5 min.
Real practices from the h3llo SOC team and our Managed customers. No fluff, no marketing.
Methodology, mapping the rule engine to techniques, hot-techniques, how to find gaps. With formulas and examples. PDF · ~30 min.
→Checklist · PDFRoster, escalation, runbooks, MTTD targets, on-call rotations. What you must set up before day-1. 12 pp · ~18 min.
→Case · bank1.2 TB/day of logs, 14 sources, with zero SOC downtime. What we rewrote in detections, what we invested in. case · ~25 min.
→Guide · 24 ppContainment, eradication, recovery. With real pre-conditions and wins/losses from 18 cases. PDF · ~30 min.
→Benchmark · 2025Numbers from Verizon DBIR, M-Trends, our Managed SOC customers. Exactly where time is lost. report · ~20 min.
→Templates · GitHubOpen-source detection rules for our SIEM. Regular commits, community contributions accepted. repo · 200+ rules.
→Install the platform, connect sources, enable 500+ detectors with MITRE mapping, configure escalation. From zero to a production-grade SOC.
`helm install h3llo-sec h3llo/security` · 1 command. Supports any input (syslog, OTLP, ECS).
Cloud (CloudTrail/Audit), on-prem (Wazuh/agent), network (NetFlow), applications. Auto-discovery covers 80%.
500+ rules out of the box with MITRE mapping. `h3 sec rules enable --all` or selectively by tactic.
Slack/Telegram/PagerDuty + war-room runbooks. The AI commander builds the incident timeline on its own.
SIEM, EDR, NGFW, IPS, WAF, DLP, MITRE, IRP — in one console. Your SOC or ours is on duty. MTTD ≤ 5 min, MTTR ≤ 20 min on typical incidents.