Open Source Security Operations Center — Public Administration
CITADEL is a fully open-source Security Operations Center platform purpose-built for public administration. Combining real-time threat detection, automated incident response, threat intelligence sharing and forensic analysis into one integrated platform — built on transparency, sovereignty and community trust. This soc.trials.vip deployment is the second-generation CITADEL platform: fully automated and replicable through GitLab CI/CD pipelines, with platform-wide Keycloak single sign-on and Wazuh agents auto-enrolled on every node.
SIEM & XDR platform. Real-time endpoint monitoring, intrusion detection, vulnerability scanning and compliance (CIS benchmarks) across all nodes.
Incident Response platform (DFIR-IRIS). Fully open-source collaborative case management with native Keycloak OIDC — evidence tracking, task assignment and timeline analysis.
Analysis engine. Automated observable analysis via 300+ analyzers — IPs, hashes, URLs, domains. Active response capabilities for threat neutralisation.
Threat Intelligence Platform. Structured sharing of indicators of compromise (IoCs), threat actors and attack patterns across trusted communities.
SOAR platform. Visual workflow automation connecting all SOC tools. Automate alert triage, enrichment, notifications and incident creation.
Identity & Access Management. Single Sign-On across all platform services via OIDC/SAML. Centralised user management and role-based access control.
Governance, Risk and Compliance (GRC) and NIS2 framework management platform for public administration.
Autonomous AI agent workflows for security operations.
Team messaging and collaboration via Mattermost.
Hybrid x86/ARM64 k3s cluster, Longhorn distributed storage, HTTPS ingress with Let’s Encrypt, GitLab CI deployment pipelines, Wazuh agents on all nodes.
DFIR-IRIS, Cortex, Shuffle, MISP, full Wazuh stack deployed and accessible. Password rotation complete.
Keycloak IAM deployed. OIDC SSO live across Wazuh, DFIR-IRIS, Cortex, MISP and Shuffle. Centralised realm citadel-soc.
Wazuh→IRIS alert pipeline. Cortex analyzers configured. Shuffle playbooks for automated triage.
MISP community feeds. IRIS↔MISP bidirectional sync. CIS benchmark remediation.
HA setup, encrypted backups, network segmentation, audit logging, security baseline 90%+.