CITADEL SOC

Open Source Security Operations Center — Public Administration

Systems Operational
Mission Statement

Defending Public Infrastructure
Through Open Intelligence

CITADEL is a fully open-source Security Operations Center platform purpose-built for public administration. Combining real-time threat detection, automated incident response, threat intelligence sharing and forensic analysis into one integrated platform — built on transparency, sovereignty and community trust. This soc.trials.vip deployment is the second-generation CITADEL platform: fully automated and replicable through GitLab CI/CD pipelines, with platform-wide Keycloak single sign-on and Wazuh agents auto-enrolled on every node.

4
Cluster Nodes
14
Active Services
GitOps
Replicable Deployment
100%
Open Source

Platform Services

Management Services

Alert Flow Architecture

Wazuh Agents → Wazuh Manager → n8n SOAR → IRIS Case → Cortex Analysis → MISP Intel → Response
Security events from monitored endpoints flow through Wazuh for detection and correlation. High-severity alerts trigger automated n8n workflows that create DFIR-IRIS cases, enrich observables via Cortex analyzers, cross-reference MISP threat intelligence, and execute active response actions — all without manual intervention.

Platform Roadmap

Phase 1 — Complete
Core Infrastructure

Hybrid x86/ARM64 k3s cluster, Longhorn distributed storage, HTTPS ingress with Let’s Encrypt, GitLab CI deployment pipelines, Wazuh agents on all nodes.

Phase 2 — Complete
SOC Services

DFIR-IRIS, Cortex, n8n, MISP, full Wazuh stack deployed and accessible. Password rotation complete.

Phase 3 — Complete
Identity & SSO

Keycloak IAM deployed. OIDC SSO live across Wazuh, DFIR-IRIS, Cortex, MISP, n8n, CISO Assistant and Paperclip. Centralised realm citadel-soc.

Phase 4 — Active
Automation Pipelines

Wazuh agents live on all nodes (auto-enrolling DaemonSet). Next: Wazuh→n8n SOAR pipeline live: alert → observable extraction → MISP + Cortex enrichment → LLM analysis → IRIS case.

Phase 5 — Upcoming
Threat Intel Feeds

MISP community feeds. IRIS↔MISP bidirectional sync. CIS benchmark remediation.

Phase 6 — Upcoming
Production Hardening

HA setup, encrypted backups, network segmentation, audit logging, security baseline 90%+.