Cybersecurity Security Operations Center (SOC)Dashboard

Authors

  • Kothapalli Keerthi, Swathi Terli, Musunuru Ratnakar Author

DOI:

https://doi.org/10.62643/

Abstract

Security Operations Centers must correlate alerts, vulnerabilities, asset health, and incident activity produced by many disconnected tools. This paper presents a Cybersecurity Security Operations Center Dashboard that consolidates these functions into a role-aware web platform. The documented implementation uses a React.js singlepage interface, an Nginx edge layer, a Node.js and Express.js REST API, JWT authentication, role-based access control, MongoDB persistence, and containerized cloud deployment. Operational modules cover dashboard key performance indicators, alert triage, signature and behavior-based threat detection, MITRE ATT&CK mapping, vulnerability and patch tracking, incident response, reporting, user administration, and settings. Prometheus and Grafana provide infrastructure monitoring, while the ELK Stack and CloudWatch support centralized logging and operational visibility. The architecture accepts telemetry from firewalls, intrusion detection systems, endpoint tools, cloud logs, and vulnerability scanners, normalizes the records, and exposes structured workflows from alert creation through investigation, containment, recovery, and closure. Representative dashboard and API outputs confirm the intended integration of security score summaries, severitybased alert counts, active incidents, server-health indicators, geolocated attack events, and auditable incident timelines. The result is a modular and scalable foundation for centralized security monitoring, faster analyst decision support, and compliance-oriented reporting.

Downloads

Published

05-08-2026

How to Cite

Cybersecurity Security Operations Center (SOC)Dashboard. (2026). International Journal of Engineering Research and Science & Technology, 22(3(1), 1744-1749. https://doi.org/10.62643/