Skip to main content

I started building a micro AI SOC for my SaaS project.

0
Medium
Published: 10/09/2026 (10/09/2026, 09:14:35 UTC)
Source: Reddit Cybersecurity

Description

This content describes the development of a micro AI-powered Security Operations Center (SOC) for a small SaaS project. The SOC integrates Wazuh for log collection and alerting, ClickHouse for event storage and fast querying, and custom Python connectors for cloud API polling. It aims to monitor all infrastructure components, detect incidents, and enable automated or semi-automated response. The architecture is designed to run on a single VM and leverages AI for investigation and response tasks. No specific vulnerability or exploit is described.

Reddit Discussion

r/cybersecurity·posted by u/denchz
00

In 10 months of development my SaaS project grew to several VMs and 10+ cloud services around them (GitHub, Cloudflare, Purelymail and so on). Basic hardening, uptime monitoring etc I always do. But I always wanted to see and control more — ideally everything that happens in every component of my infra.
I want to know whether someone got access to my server, created an illegitimate GitHub token, or is brute-forcing a database I accidentally exposed to the internet — and ideally I want respond to it automatically.

So I started an experiment: building a micro AI SOC for my project. And what I like most is that here I have much more freedom to give AI broad permissions for investigation and response than in the infrastructure of big companies.

𝐇𝐨𝐰 𝐢𝐭'𝐬 𝐛𝐮𝐢𝐥𝐭 𝐚𝐭 𝐭𝐡𝐞 𝐦𝐨𝐦𝐞𝐧𝐭:

→ Everything lives on one VM with 6 vCPU and 16 GB of RAM. The whole SOC currently uses about 2.4 GB: 1.5 GB for ClickHouse, 0.5 GB for Wazuh, the rest are connectors and services at a few dozen MB each.

→ 55–75 thousand events a day, about 0.6–0.9 EPS.

→ Wazuh agents on the servers send events to the SOC.

→ Wazuh manager collects the logs and generates alerts. Its bundled OpenSearch indexer I dropped — it's too heavy. For storage I use ClickHouse instead.

→ Wazuh and ClickHouse are connected through a file: Wazuh writes every event to archives.json, Vector reads the file and writes to ClickHouse. On the way Vector filters out the noise. ClickHouse compresses the rest almost 8 times and runs investigation queries fast.

→ Tiny Python connectors poll the cloud APIs every 10–15 minutes: hosting, Cloudflare, email, GitHub and so on. For a service with no audit log, the connector takes a snapshot of the settings and records what changed.

→ GitHub webhooks come in through a Cloudflare tunnel.

→ My own detector periodically runs detection rules on ClickHouse and writes alerts back into a separate table. It's needed because cloud events bypass Wazuh. Unfortunately, I couldn't keep all the detection rules in one place.

→ A correlator looks at incoming alerts and decides: open a new incident, add the alert to an open one, or not open an incident at all. It also determines urgency.

→ PostgreSQL keeps the incidents: statuses, participants, timeline and response actions.

→ A separate service watches that no source goes silent, and messages me only if it can't figure out the reason itself.

→ All architecture principles and decisions live in a git repository, so the SOC can be reproduced from it. Closed incidents land there as Markdown reports.

Full write-up with diagrams (I’m the author): https://denzuikov.substack.com/p/building-an-ai-soc-for-my-small-projects

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 14:33:19 UTC

Technical Analysis

The author built a micro AI SOC on a single VM with 6 vCPUs and 16 GB RAM to monitor a SaaS project infrastructure consisting of multiple VMs and cloud services. Wazuh agents collect logs and generate alerts, which are stored in ClickHouse after filtering by Vector. Custom Python connectors poll cloud APIs and capture configuration snapshots. A separate detector runs queries on ClickHouse to generate alerts for cloud events that bypass Wazuh. A correlator aggregates alerts into incidents, manages incident statuses, and determines urgency. Incident data is stored in PostgreSQL, and closed incidents are archived as Markdown reports in a git repository. The SOC portal allows querying infrastructure status in free form. The entire SOC architecture and processes are documented in a git repository for reproducibility. The project is experimental and designed to give AI broad permissions for investigation and response in a small-scale environment.

Potential Impact

No direct security vulnerability or exploit is described. The content relates to the design and implementation of a security monitoring and incident response system for a small SaaS project. The impact is operational: improved visibility and control over infrastructure security events, potentially reducing risk by faster detection and response. There is no indication of an active threat or compromise.

Defensive Guidance

No mitigation is required as this is not a vulnerability or active threat. The content describes a security monitoring architecture. Organizations interested in similar capabilities may consider adopting or adapting such an AI-assisted SOC approach, but no urgent action or patching is needed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac8fb2a2cdf04f6565df553

Added to database: 10/09/2026, 14:33:14 UTC

Last enriched: 10/09/2026, 14:33:19 UTC

Last updated: 10/09/2026, 16:48:13 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses