About SOCRoot

A cybersecurity product initiative, documented in public.

SOCRoot is Mu'ath Yousef's independent cybersecurity product initiative. It is developing automatable subscription services for smaller organizations and validating whether each service produces measurable value customers will pay to receive repeatedly. Project Synapse remains a separate open-source graduation project.

The builder

Mu'ath Yousef

Cybersecurity graduate from Tafila Technical University, focused on SOC engineering, security automation, architecture, and operational evidence.

The public repositories show both implemented work and its limits. They deliberately avoid presenting planned modules, synthetic demonstrations, or incomplete integrations as customer outcomes or production guarantees.

Focus

Current engineering areas

SOC engineering

Detection, case handling, evidence capture, and operator-centered incident workflows.

Security automation

Dry-run-first orchestration with human approval, audit records, and rollback requirements.

System architecture

Clear boundaries between SOCRoot product work, reusable technical assets, and the separate Project Synapse graduation project.

Responsible AI integration

AI-assisted analysis that records uncertainty and avoids sending raw client data to external providers.

Evolution

Two independent tracks

Academic track

Project Synapse

An open-source graduation project combining cybersecurity workflows, data analytics, and a scalable modular architecture.

Commercial track

SOCRoot

An independent product initiative focused on automatable cybersecurity subscription services with measurable, repeatable customer value.

Current

Pre-production commercial validation

The current focus is selecting narrow service problems, validating willingness to pay, and proving safe delivery with explicit evidence gates.

Principles

How the work is evaluated

01

Evidence before claims

A capability is described as verified only when tests, deployment evidence, limitations, and rollback behavior can be reviewed.

02

Human control for sensitive actions

High-impact remediation is never presented as unattended automation. Dry-run and explicit approval are the default.

03

Client data stays bounded

Raw client data is not published, reused as portfolio material, or sent to external AI providers without explicit authorization.

04

Architecture should reveal uncertainty

Pre-production status, incomplete integrations, assumptions, and safety constraints belong in the public engineering record.

Repository map

Review the public record by responsibility

Start with value, scope, and evidence

A useful engagement begins with authorization, a narrow customer problem, measurable outcomes, and evidence requirements—not a promise of unattended production capability.