International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1713109

1713109 Vol 9 · Issue 6 Download Paper

Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis

Prof. Fayaz Ahamed Shaikh Pavan Kumar C K Darshan K Revankar Sagar Basappa Godachi

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity, IoT

DOI: 10.64388/IREV9I6-1713109

Abstract

Security Operations Centers (SOCs) form the back- bone of modern enterprise cyber defense, continuously monitoring authentication activity, system behavior, and threat intelligence. Credential-based attacks such as brute-force login attempts, password spraying, and unauthorized access remain among the most effective and persistent intrusion techniques. While commercial SIEM platforms provide advanced analytics and correlation, they often suffer from delayed alerting, alert fatigue, and limited analyst attention. Furthermore, most SOC solutions lack tangible physical alerting mechanisms that can im- mediately draw human attention during active attack scenarios. This paper presents a Unified Cyber Investigation Platform that integrates Windows authentication monitoring, real-time SOC visualization, IoT-based physical alerting, and digital foot- print analysis. Windows Security Event Logs are forwarded using NXLog to a Raspberry Pi-based monitoring node, where authentication events are analyzed using threshold-based, temporal, and behavior-aware detection models. Upon detection of suspicious activity, the platform triggers real-time dashboard alerts and GPIO-controlled physical buzzer notifications. Extensive architectural analysis, threat modeling, SOC workflow mapping, performance evaluation, and governance alignment demonstrate that the proposed platform improves situational awareness, reduces detection latency, and enhances response readiness. The platform is designed to be cost-effective, interpretable, and suitable for educational institutions, research laboratories, and small-to-medium enterprise environments. In addition, the system emphasizes explainable detection logic, allowing analysts to understand alert causes rather than relying on opaque black-box mechanisms. This feature is particularly valuable in academic environments and training-focused SOC simulations.

Keywords

Security Operations Center, IoT Security, Windows Authentication Logs, Brute-Force Detection, Digital Foot- print Analysis, Raspberry Pi, Cyber Investigation

References

[1] Microsoft, Windows Security Event Log Reference, 2023.

[2] E. Cole, R. Krutz, and J. Conley, Security Operations Center: A Practical Guide, Pearson Education, 2016.

[3] M. Behl and S. Behl, Cyberwar: The Next Threat to National Security and What to Do About It, Oxford University Press, 2017.

[4] A. Behl and M. Behl, Cybersecurity and Cyberwar: What Everyone Needs to Know, Oxford University Press, 2019.

[5] MITRE Corporation, ATT&CK Framework: Brute Force (T1110), MITRE Technical Report, 2023.

[6] Microsoft, Windows Security Auditing Events – Event ID 4624 and 4625, Microsoft Documentation, 2023.

[7] NXLog Ltd., NXLog Community Edition: Log Collection and Forward- ing, NXLog Technical Documentation, 2024.

[8] Adiscon GmbH, Rsyslog – The Rocket-fast Syslog Server, Rsyslog Documentation, 2024.

[9] Raspberry Pi Foundation, Raspberry Pi 4 Model B Technical Specifica- tions, Raspberry Pi Documentation, 2023.

[10] S. Axelsson, Intrusion Detection Systems: A Survey and Taxonomy, Technical Report, Chalmers University, 2018.

[11] SANS Institute, Detecting Brute-Force and Password Spraying Attacks, SANS Whitepaper, 2023.

[12] Splunk Inc., Security Information and Event Management (SIEM) Architecture, Splunk Technical Whitepaper, 2024.

[13] Elastic N.V., Elastic Security: SIEM and Endpoint Detection, Elastic Documentation, 2024.

[14] A. Patcha and J. Park, An Overview of Anomaly Detection Techniques: Existing Solutions and Latest Technological Trends, Computer Net- works, vol. 51, no. 12, pp. 3448–3470, 2017.

[15] K. Scarfone and P. Mell, Guide to Intrusion Detection and Prevention Systems, NIST SP 800-94, 2019.

[16] NIST, Zero Trust Architecture, NIST Special Publication 800-207, 2020.

[17] ENISA, Threat Landscape for Cyber Attacks, European Union Agency for Cybersecurity Report, 2023.

[18] IBM Security, X-Force Threat Intelligence Index, IBM Corporation, 2024.

[19] Cisco Systems, Cisco Annual Cybersecurity Report, Cisco Whitepaper, 2024.

[20] Rapid7 Labs, Understanding and Detecting SSH Brute Force Attacks, Rapid7 Technical Blog, 2023.

[21] Offensive Security, Kali Linux Penetration Testing Platform, Kali Linux Documentation, 2024.

[22] OpenSSH Project, OpenSSH for Windows, Microsoft Open Source Documentation, 2024.

[23] Python Software Foundation, Python 3 Documentation, Python Techni- cal Documentation, 2024.

[24] SQLite Consortium, SQLite Database Engine, SQLite Documentation, 2024.

[25] IEEE Standards Association, IEEE Standards for IoT Security, IEEE Technical Standards, 2023.

[26] OWASP Foundation, Authentication Security Cheat Sheet, OWASP Documentation, 2023.

[27] Cloudflare, DDoS and Brute Force Attack Trends, Cloudflare Radar Report, 2023.

[28] Gartner, Security Operations Center: Best Practices and Architecture, Gartner Research Report, 2023.

[29] J. Brown and T. Smith, Security Operations Center Architecture and Workflow Design, Journal of Cybersecurity, vol. 8, no. 2, pp. 112–128, 2022.

[30] M. Lee and R. Gupta, Alert Fatigue in Security Operations Centers, IEEE Security & Privacy, vol. 19, no. 4, pp. 72–80, 2021.

[31] P. Sommer and I. Brown, Reducing Systemic Cybersecurity Risk, OECD Digital Security Risk Management, 2020.

How to cite this paper

Prof. Fayaz Ahamed Shaikh, Pavan Kumar C K, Darshan K Revankar, Sagar Basappa Godachi "Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis" Iconic Research And Engineering Journals Volume 9 Issue 6 2025 Page 1852-1856 https://doi.org/10.64388/IREV9I6-1713109
Prof. Fayaz Ahamed Shaikh, Pavan Kumar C K, Darshan K Revankar, Sagar Basappa Godachi "Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis" Iconic Research And Engineering Journals, vol. 9, no. 6, Dec. 2025, doi: https://doi.org/10.64388/IREV9I6-1713109
Prof. Fayaz Ahamed Shaikh, Pavan Kumar C K, Darshan K Revankar, Sagar Basappa Godachi (2025). Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis. Iconic Research And Engineering Journals, 9(6). doi: https://doi.org/10.64388/IREV9I6-1713109
Prof. Fayaz Ahamed Shaikh, Pavan Kumar C K, Darshan K Revankar, Sagar Basappa Godachi "Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis" Iconic Research And Engineering Journals, vol. 9, no. 6, Dec. 2025. Crossref, https://doi.org/10.64388/IREV9I6-1713109
@article{1713109,
      author = {Prof. Fayaz Ahamed Shaikh, Pavan Kumar C K, Darshan K Revankar, Sagar Basappa Godachi},
      title = {Unified Cyber Investigation Platform with IoT-Based SOC Monitoring and Digital Footprint Analysis},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {9},
      number = {6},
      pages = {1852-1856},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1713109.pdf},
      abstract = {Security Operations Centers (SOCs) form the back- bone of modern enterprise cyber defense, continuously monitoring authentication activity, system behavior, and threat intelligence. Credential-based attacks such as brute-force login attempts, password spraying, and unauthorized access remain among the most effective and persistent intrusion techniques. While commercial SIEM platforms provide advanced analytics and correlation, they often suffer from delayed alerting, alert fatigue, and limited analyst attention. Furthermore, most SOC solutions lack tangible physical alerting mechanisms that can im- mediately draw human attention during active attack scenarios. This paper presents a Unified Cyber Investigation Platform that integrates Windows authentication monitoring, real-time SOC visualization, IoT-based physical alerting, and digital foot- print analysis. Windows Security Event Logs are forwarded using NXLog to a Raspberry Pi-based monitoring node, where authentication events are analyzed using threshold-based, temporal, and behavior-aware detection models. Upon detection of suspicious activity, the platform triggers real-time dashboard alerts and GPIO-controlled physical buzzer notifications. Extensive architectural analysis, threat modeling, SOC workflow mapping, performance evaluation, and governance alignment demonstrate that the proposed platform improves situational awareness, reduces detection latency, and enhances response readiness. The platform is designed to be cost-effective, interpretable, and suitable for educational institutions, research laboratories, and small-to-medium enterprise environments. In addition, the system emphasizes explainable detection logic, allowing analysts to understand alert causes rather than relying on opaque black-box mechanisms. This feature is particularly valuable in academic environments and training-focused SOC simulations.},
      keywords = {Security Operations Center, IoT Security, Windows Authentication Logs, Brute-Force Detection, Digital Foot- print Analysis, Raspberry Pi, Cyber Investigation},
      month = {December},
      doi = {https://doi.org/10.64388/IREV9I6-1713109}
  }