Authorized attack-surface discovery
Passive discovery and scoped scanning patterns for assets whose ownership and authorization are explicitly documented.
SOCRoot is an independent cybersecurity product initiative developing automatable subscription services for smaller organizations. Each service must deliver measurable, repeatable customer value while keeping maturity, risk, authorization, and operational limits explicit.
Pre-production
Current maturity
HITL
Sensitive actions
Dry-run
Default response mode
Subscription
Commercial model under validation
Service foundations
These capabilities are being tested as building blocks for subscription services—not presented as an unattended, production-grade managed SOC.
Passive discovery and scoped scanning patterns for assets whose ownership and authorization are explicitly documented.
A workflow for enriching findings, reducing noise, recording decisions, and keeping the original evidence traceable.
Sensitive remediation is proposed in dry-run mode and requires an operator decision, an audit record, and a rollback path.
Engineering work around Wazuh, case management, and alert transport, with production claims gated by deployment evidence.
Structured findings, remediation context, and decision evidence designed to make technical work reviewable by operators and stakeholders.
Explicit boundaries between the SOCRoot product surface, its candidate control plane, reusable assets, and the separate Project Synapse graduation project.
Operating model
Confirm authorization, asset ownership, exclusions, data-handling rules, and success criteria before any security activity.
Collect security signals through approved sources while preserving timestamps, provenance, and client boundaries.
Enrich and prioritize findings, flag uncertainty, and route high-impact decisions to a human operator.
Apply only approved actions, verify the result, capture evidence, and retain a documented rollback path.
Open engineering record
The public record separates SOCRoot product work from Project Synapse and labels implementation maturity so each claim can be reviewed in context.
An open-source graduation project combining security operations, data analytics, and a scalable modular architecture.
Open public documentation →Private product engineeringA candidate foundation for portals, RBAC, client state, evidence workflows, and observability; adoption depends on service validation.
Open public documentation →Private graduation-project engineeringAlert ingestion, triage, human approval, and evidence capture for Project Synapse. Reuse by SOCRoot requires an explicit interface and value case.
Open public documentation →Start with a clearly bounded problem, authorization, expected evidence, and the recurring value the service should deliver. Current offerings remain subject to pre-production validation.