Skip to main content

๐Ÿ›ก๏ธ SOC Toolkit v7.0

โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ•—     โ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—
โ–ˆโ–ˆโ•”โ•โ•โ•โ•โ•โ–ˆโ–ˆโ•”โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ•โ•โ•    โ•šโ•โ•โ–ˆโ–ˆโ•”โ•โ•โ•โ–ˆโ–ˆโ•”โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•‘     โ–ˆโ–ˆโ•‘ โ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘โ•šโ•โ•โ–ˆโ–ˆโ•”โ•โ•โ•
โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘            โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘     โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ• โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘   
โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘            โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•‘     โ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•— โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘   
โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•‘โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—       โ–ˆโ–ˆโ•‘   โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•‘  โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘   
โ•šโ•โ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ•  โ•šโ•โ•โ•โ•โ•โ•       โ•šโ•โ•    โ•šโ•โ•โ•โ•โ•โ•  โ•šโ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ•โ•โ•šโ•โ•  โ•šโ•โ•โ•šโ•โ•   โ•šโ•โ•   

โšก Global Enterprise Threat Intelligence & Incident Response Platform

Python 3.8+ License: MIT Version Docker Kubernetes


โšก Quick Start

# 1. Install via pip
pip install soc-toolkit

# 2. Perform instant Zero-Key Threat Intel Lookup with AI Triage
soc 185.220.101.45

# 3. Launch Interactive Analyst Terminal Shell
soc shell

# 4. Start Enterprise REST API Server
soc server --port 8000

# 5. Launch 3D Cyber Threat Warfare Dashboard
soc web --port 8080

๐Ÿ”ฅ Features at a Glance

Feature Description Command
๐Ÿฆ  Zero-Key VirusTotal / Shodan / AbuseIPDB API Key-Free public VirusTotal, Shodan (CVEs & Risk Grade A-F), AbuseIPDB & Cisco Talos soc <ioc>
๐Ÿค– Autonomous AI Analyst Root Cause Analysis (RCA) & Cyber Kill Chain Attribution soc ai <ioc>
๐Ÿ“ก Live Syslog Stream Real-time UDP 514 Syslog listener with Slack/Teams Webhook alerts soc stream
๐Ÿงฌ Memory & Mimikatz Forensics Process memory dump parser & LSASS credential theft hunter soc mem <file>
๐Ÿ”Œ Enterprise EDR Collector CrowdStrike Falcon, Defender & SentinelOne process tree telemetry soc edr <host>
๐ŸŒ Attack Surface Management (EASM) Subdomain discovery, open ports, HSTS/CSP security headers & Shadow IT soc asm <domain>
๐Ÿ’€ Ransomware Gang Matcher LockBit 3.0, BlackCat/ALPHV, Clop & RansomHub TTP matching soc ransomware <ioc>
๐Ÿ“„ Executive Incident Tickets 1-Click Jira & ServiceNow Incident Response ticket generator soc report <ioc>
โฑ๏ธ C2 Beaconing Calculator Connection interval delta variance & heartbeat detection soc beacon
๐Ÿ—ฃ๏ธ Multi-Language Reports Generates reports in English, Turkish, German, French, Spanish & Japanese soc i18n <ioc> de
๐Ÿ”„ Automated SOAR Engine Executes containment, host isolation & firewall bans soc soar <ioc>
๐Ÿ“œ Regulatory Compliance Maps findings to PCI-DSS 4.0, ISO 27001, SOC 2 & NIST CSF soc audit <ioc>
๐Ÿ•ธ๏ธ 3D Threat Dashboard High-tech WebGL cyber warfare threat map soc web --port 8080

๐Ÿค– Autonomous AI Security Analyst

Run instant AI triage on any IP, Domain, Hash, or URL:

soc ai 185.220.101.45
{
  "ioc": "185.220.101.45",
  "threat_level": "CRITICAL",
  "cyber_kill_chain_phase": "Command and Control (C2) / Exfiltration",
  "root_cause_analysis": "Autonomous AI Analysis concluded an overall risk score of CRITICAL. Attribution indicates active alignment with Cyber Kill Chain phase: 'Command and Control (C2)'. Network containment recommended.",
  "ciso_executive_summary": "EXECUTIVE SUMMARY: Indicator 185.220.101.45 poses a CRITICAL risk to enterprise operations. Authorize automated SOAR containment."
}

๐Ÿ“œ Regulatory Compliance Frameworks Supported

Framework Controls Mapped Command
PCI-DSS 4.0 Req 6.4 (App Security), Req 10.4 (Audit Telemetry), Req 11.4 (Threat Defense) soc audit <ioc>
ISO/IEC 27001:2022 Control A.8.7 (Malware Defense), A.8.16 (Monitoring), A.8.23 (Web Filtering) soc audit <ioc>
SOC 2 Type II CC6.1 (Access Controls), CC6.8 (Threat Detection), CC7.2 (Incident Response) soc audit <ioc>
NIST CSF 2.0 DE.CM-01 (Continuous Monitoring), RS.AN-01 (Incident Analysis) soc audit <ioc>

๐Ÿณ 1-Click Container Deployment

# Docker Compose 1-Click Launch
docker-compose up -d

# Kubernetes Production Deployment
kubectl apply -f k8s/deployment.yaml

๐Ÿ Python SDK

from soc_toolkit import SOCToolkitSDK, AIThreatAnalyst, SOAREngine, IOCType, ThreatLevel

sdk = SOCToolkitSDK()

# Analyze IOC
report = sdk.analyze("185.220.101.45")

# Autonomous AI Triage
ai_triage = AIThreatAnalyst.analyze_threat("185.220.101.45", IOCType.IP, ThreatLevel.CRITICAL)
print("Kill Chain Phase:", ai_triage["cyber_kill_chain_phase"])

๐Ÿ‘ค Author & License

Metadata

Release files for soc-toolkit 7.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for soc-toolkit 7.0.1
File Size Uploaded
soc_toolkit-7.0.1.tar.gz 80.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for soc-toolkit 7.0.1
File Interpreter ABI Platform
soc_toolkit-7.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 179.0 kB

Release files / soc_toolkit-7.0.1.tar.gz

Download URL soc_toolkit-7.0.1.tar.gz
Size 80.3 kB
Tags Source
SHA-256 checksum
How to use checksums
bd2b9eaac812eb7bd75c76f891f1f58ff67cdde87cf5012aa7d0ee0292d60c8f
BLAKE2b-256 checksum
How to use checksums
b91dfd418000363d3e2b165ab28e99c283927317d8dcf0e390b61664b6e2ed22
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.1

Release files / soc_toolkit-7.0.1-py3-none-any.whl

Download URL soc_toolkit-7.0.1-py3-none-any.whl
Size 98.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
300459273970a5fe204fca0a691bbf5c019518070b4ef165e8da56565ecaf1a0
BLAKE2b-256 checksum
How to use checksums
41e26a680abdf72c0bb00f2c5460290b69458e445ec40a4d005ac010ade8d0e0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.1

Release history Release notifications | RSS feed

This release

7.0.1 This release

2 release files

7.0.0

2 release files

6.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page