Designing a Lightweight Proactive Threat Detection Framework Using Open-Source SOC Tools for Mid-Sized Enterprises
Proposes a modular, proactive threat detection framework built on open-source SOC tools to address the visibility and operational gaps facing mid-sized enterprises. The framework correlates network, endpoint, identity, and cloud telemetry to enable earlier detection of credential misuse, lateral movement, and anomalous access — without dependence on costly commercial platforms. Validated through a containerized proof-of-concept demonstrating deterministic anomaly detection and zero false positives under benign conditions.