SOC Wazuh + TheHive + Cortex + MISP (attaque & défense) mode Red Team - MITM et Blue Team - TLS1.3

In this video, AcadiaCyberSec showcases a SOC in real-world conditions. The goal is to demonstrate the power of a modern SOC… but also the risks when the infrastructure is not properly secured. ━━━━━━━━━━━━━━━━━━ 🔴 PART 1 — VULNERABLE SOC (MITM Attack) ━━━━━━━━━━━━━━━━━━ We deploy a SOC infrastructure composed of: • Wazuh • TheHive (HTTP by default) • Cortex (HTTP by default) • MISP We then simulate a real-world incident: A Linux server attempts to communicate with a malicious public IP address identified by MISP. Real-time SOC workflow: • Automatic case creation in TheHive • Enrichment via Cortex & MISP • Threat correlation • Complete incident visibility BUT… we also show the reality on the ground: TheHive & Cortex platforms run over HTTP → internal MITM attack! We intercept: • SOC administration sessions • Internal communications • Nmap reconnaissance of SOC servers Even a SOC can be vulnerable if it is poorly secured. ━━━━━━━━━━━━━━━━━━ 🟢 PART 2 — SECURE SOC (Zero Trust Architecture) ━━━━━━━━━━━━━━━━━━ We are rebuilding the architecture with enhanced security: • NGINX Reverse Proxy for TheHive, Cortex, and DVWA • 100% HTTPS Infrastructure • Secure communication between all SOC components New incident simulation: An internal server contacts a malicious C2 domain. Detection chain: 1. Wazuh generates an alert 2. TheHive automatically creates a case 3. Cortex enhances the incident 4. MISP confirms the threat 5. Complete analysis in HTTPS SOC is much more resilient and difficult to attack. ━━━━━━━━━━━━━━━━━━ What you will learn: • Modern SOC architecture • Automated Incident Response • Real-time C2 detection • Internal HTTP risks • MITM in SOC networks • Security via Reverse Proxy • Real Blue Team workflow ━━━━━━━━━━━━━━━━━

She Was Trying to Cut It With Scissors and The Grass Was Taller Than My Mowers
▶︎

She Was Trying to Cut It With Scissors and The Grass Was Taller Than My Mowers

Shade Tree Used Car Lot Strikes AGAIN! (Customer JUST BOUGHT this CAR) 2007 Kia Optima 2.4
▶︎

Shade Tree Used Car Lot Strikes AGAIN! (Customer JUST BOUGHT this CAR) 2007 Kia Optima 2.4

Full Body Strength Workout | Build Muscle Over 40
▶︎

Full Body Strength Workout | Build Muscle Over 40

America's Got Talent 2026 ALL AUDITIONS | Week 2
▶︎

America's Got Talent 2026 ALL AUDITIONS | Week 2

Create Your AI Cybersecurity Agent with n8n Step-by-Step (Persistent Memory + Research)
▶︎

Create Your AI Cybersecurity Agent with n8n Step-by-Step (Persistent Memory + Research)

OPNSense 26.1 - Installation - Configuration - Exploring New Security Features Q-Feeds
▶︎

OPNSense 26.1 - Installation - Configuration - Exploring New Security Features Q-Feeds

Birds Singing in a Tranquil Forest 🌳  Nature Sounds for Deep Sleep and Calm Mind
▶︎

Birds Singing in a Tranquil Forest 🌳 Nature Sounds for Deep Sleep and Calm Mind

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
▶︎

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
▶︎

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

How to Learn Python | Python Programming | Learn Python | Intellipaat
▶︎

How to Learn Python | Python Programming | Learn Python | Intellipaat

SOC Open Source, ELK- TheHive- Cortex- MISP Complete Setup Guide, Part 1
▶︎

SOC Open Source, ELK- TheHive- Cortex- MISP Complete Setup Guide, Part 1

#1 Cyber-SOC - Configuring TheHive and Cortex for a SOC with Wazuh Part 1
▶︎

#1 Cyber-SOC - Configuring TheHive and Cortex for a SOC with Wazuh Part 1

Ads are now police surveillance
▶︎

Ads are now police surveillance

How to Start Coding | Programming for Beginners | Learn Coding | Intellipaat
▶︎

How to Start Coding | Programming for Beginners | Learn Coding | Intellipaat

We Completely Changed Our BRAND NEW Van… First Full Tour
▶︎

We Completely Changed Our BRAND NEW Van… First Full Tour

Cybersecurity Architecture: Who Are You? Identity and Access Management
▶︎

Cybersecurity Architecture: Who Are You? Identity and Access Management

Linux for Hackers Tutorial (And Free Courses)
▶︎

Linux for Hackers Tutorial (And Free Courses)

#3 Cyber-SOC Wazuh Integration TheHive-Cortex Cortex-MISP TheHive-MISP - Cyber-Geostrategy
▶︎

#3 Cyber-SOC Wazuh Integration TheHive-Cortex Cortex-MISP TheHive-MISP - Cyber-Geostrategy

Shuffle + Wazuh + TheHIVE + Cortex = Automation Bliss
▶︎

Shuffle + Wazuh + TheHIVE + Cortex = Automation Bliss

HA Implementation of remote security policies in private clouds WServer 2025–pfSense
▶︎

HA Implementation of remote security policies in private clouds WServer 2025–pfSense