Description
This ongoing project develops an automation-first security monitoring framework that detects attack-surface drift and correlates it with continuous web vulnerability intelligence to produce decision-grade security evidence for modern SOC operations. Rather than relying on isolated or periodic scans, the framework operates on a fixed five-minute cadence, continuously reassessing exposure, validating persistence, and correlating findings across multiple tools.
Approach
The system integrates IDS-like exposure monitoring with scheduled vulnerability assessment using Nmap (service discovery and reachability), Nikto (web server misconfiguration and exposure), and OWASP ZAP Baseline (automation-friendly DAST). Results are normalized, stored as time-stamped evidence, and correlated across monitoring cycles so that persistent and reachable weaknesses are prioritized over transient noise.
Key Innovations
Detection of exposure drift (new or disappearing ports/services)
Time-based correlation to distinguish persistent risk from one-off artifacts
Cross-tool agreement to increase confidence and reduce false positives
Explicit handling of coverage gaps to prevent false assurance
SOC-aligned workflow supporting triage, response, and verification
Validation Environment
The framework is evaluated in a controlled lab using intentionally vulnerable systems (Kioptrix 2 and Metasploitable 2) monitored from a Kali Linux sensor, following ethical and legal testing boundaries. The architecture emulates enterprise deployment patterns using DMZ-style network segmentation.
Outcomes (to date)
Preliminary results demonstrate faster prioritization, clearer attack-path visibility, and improved analyst confidence by converting raw scanner output into time-validated, correlated risk evidence. The system performs effectively in both low-signal environments (few high-impact issues) and high-signal environments (dense vulnerability data).
Status
Ongoing -Active development and refinement
Planned extensions include AI-assisted alert scoring, SOC dashboarding, and integration with SIEM platforms for real-time security analytics.
Core Technologies
Python · Nmap · Nikto · OWASP ZAP · Kali Linux · SOC workflows · Continuous Monitoring · Vulnerability Automation