Hazem Elbaz

AI-Driven SOC Automation

๐Ÿง  AI-Driven SOC Automation

Welcome to my specialization page on AI-Driven Security Operations Center (SOC) Automation, where I blend my background in cybersecurity with cutting-edge AI tooling. This page documents my research journey, open-source projects, publications, and blog reflections.


๐Ÿ” Why AI for SOC?

Modern SOCs face alert overload, analyst fatigue, and increasing attack complexity. My focus is on using LLMs to:


๐Ÿš€ Key Projects

๐Ÿ”ธ LLM-SOC-Agent

An intelligent SOC pipeline using DistilRoBERTa + LoRA for log enrichment, clustering, and alert contextualization.

๐Ÿ”ธ Log Analyzer LLM

Exploration of log summarization using pretrained LLMs and prompting.

๐Ÿ”ธ Log Anomaly Detection

Research experiments on 2024 datasets including IoTID20-Extended and LR-HR-DDoS2024.

๐Ÿ”ธ AI-SOC Datasets

Preprocessed datasets for reproducible SOC experiments (CIC-IDS 2018, SOC-Sim).


๐Ÿ“‘ Research & Publications

๐Ÿ“ In Progress:
LLM-Powered SOC Automation: Reducing MTTR with Context-Aware Agents
A 6-week study exploring LLM-based triage versus traditional SOAR rules.
โ†’ GitHub Draft


๐Ÿ—บ๏ธ Project Roadmap

๐Ÿ”— See full roadmap


โœ๏ธ Blog Series


๐Ÿ”— Recent LinkedIn Posts


๐Ÿ‘ฅ AI-SOC Automation โ€“ Team Structure

This document outlines the team organization, roles, and responsibilities for the AI-SOC Automation project.


๐Ÿ›ก๏ธ 1. AI Threat Intelligence Team

Name / Role Description Key Tasks
Lead Threat Analyst Oversees threat research & taxonomy alignment Build threat models, manage threat DB, publish intelligence reports
ML Threat Engineer Translates threats into ML-friendly formats Encode attack patterns, simulate threats, design synthetic log generators

๐Ÿง  2. AI Engineering Team

Name / Role Description Key Tasks
AI Lead Architect Designs AI pipelines and evaluation strategies Define LLM tasks, model selection, pipeline integration
Prompt Engineer Engineers and optimizes LLM prompts Design multi-step prompts, few-shot examples, test prompt behavior
Evaluation Lead Builds evaluation frameworks for LLM output Design metrics, automated graders, evaluation reports

๐Ÿ”ง 3. System Engineering & Integration Team

Name / Role Description Key Tasks
DevOps Engineer Deploys and monitors system pipelines CI/CD setup, containerization, logging infrastructure
Integration Developer Connects LLM pipeline with real-world SOC data Build APIs, connectors for SIEM logs, API testing

๐Ÿ“Š 4. Visualization & Reporting Team

Name / Role Description Key Tasks
Data Analyst Designs and analyzes classification output Generate charts, analyze performance over time
UI/UX Designer Designs dashboards or simple visual interfaces Create interfaces for reviewing triaged logs

๐Ÿ“ 5. Documentation & Coordination Team

Name / Role Description Key Tasks
Technical Writer Maintains project documentation, READMEs, tutorials Write README, API docs, usage instructions
Project Coordinator Tracks progress, team sync, and timeline adherence Standups, manage GitHub issues, maintain roadmap

๐Ÿ“Œ Notes


๐ŸŽ™๏ธ Talks & Media

๐ŸŽค Planning upcoming sessions on:


๐Ÿ‘ฃ Follow the Journey

๐ŸŒ GitHub Org: ai-soc-automation
๐Ÿง  Research Blog
๐Ÿ”— LinkedIn Weekly Posts