Catnip Games International: SOC Automation and Incident Response Platform

University:
Roehampton University
Subject:
Cybersecurity / Security Operations

Assignment Overview

This cybersecurity project presents the design and implementation of a prototype Security Operations Centre (SOC) automation and incident-response platform for Catnip Games International. The scenario addresses security challenges affecting a gaming organisation operating more than 300 Linux servers across two data centres, including credential-stuffing bot attacks, compromised player accounts, phishing campaigns and delayed coordination during security incidents. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The proposed solution integrates TheHive 5, Cortex 3, Elasticsearch, Cassandra and Python-based automation, with MISP explored for threat-intelligence integration. TheHive functions as the central incident and case-management platform, Cortex provides automated observable analysis, Elasticsearch supports search and log storage, Cassandra provides persistent case and alert storage, and Python scripts automate alert ingestion and workflow activities through REST APIs. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Implementation includes environment configuration, Docker deployment, API integration, automated alert generation, incident-response playbooks, KPI monitoring and backup procedures. Three attack scenarios are modelled: bot attacks, account takeover and phishing. Alerts are automatically ingested into TheHive, converted into cases and processed through analyst triage, investigation and resolution workflows. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The project also develops structured response playbooks covering triage, containment, investigation, recovery and post-incident actions for each security scenario. Operational metrics are visualised through a KPI dashboard measuring alert volumes, response times, Mean Time to Detect (MTTD), Mean Time to Respond/Resolve (MTTR) and platform availability. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Overall, the work demonstrates practical application of SOC architecture, security automation, incident management, threat analysis, containerised infrastructure, API-based integration, operational metrics and cyber-response procedures within a realistic gaming-industry security scenario. Catnip_Games_SOC_Complete Overview word count: approximately 330 words. Important before putting the presentation on a public Reference Library: redact any API keys/authentication tokens and other live credentials shown in the technical slides. The presentation includes API-key material in the Cortex and Python automation sections, so those credentials should also be revoked/rotated if they were ever active. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete

Megaminds Experience

Megaminds has supported academic requirements in cybersecurity / security operations and related disciplines.