# SOC Workflow App Community Edition for ELK Stack

**URL:** <https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184>\
**Category:** Kibana\
**Created:** [November 2, 2018, 2:42pm UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184 "2018-11-02T14:42:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Vdovin](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Andrew\_Vdovin](https://discuss.elastic.co/u/Andrew_Vdovin)\
**Post date:** [November 2, 2018, 2:42pm UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/1 "2018-11-02T14:42:44Z")

</div>

SOC Workflow App Community Edition for ELK Stack is released!  
SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at Elastic stack and view Saved Searches saved by teammates. Carry out investigations based on automatically generated alerts from SIEM, EDR, IDS arriving at Elastic stack, Elastic Machine Learning alerts and Threat Intelligence data enrichments from Anomali ThreatStream & MISP.

 ![socworkflow](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2f84b6ca2fbdd4a8aad83f3d8ecc0724a0dc429.jpeg)  
Download it for free from Threat Detection Marketplace: [https://tdm.socprime.com/tdm/info/1338/](https://tdm.socprime.com/tdm/info/1338/)  
Or from Github [https://github.com/socprime/soc\_workflow\_app\_ce](https://github.com/socprime/soc_workflow_app_ce)

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 2, 2018, 3:37pm UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/2 "2018-11-02T15:37:41Z")

</div>

pinging @crayzeigh

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![whoami](https://avatars.discourse-cdn.com/v4/letter/w/a9a28c/32.png) [@whoami](https://discuss.elastic.co/u/whoami)\
**Post date:** [November 12, 2018, 2:10am UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/3 "2018-11-12T02:10:59Z")

</div>

any github address?

---

<div class="post-metadata">

**Author:** ![Andrew\_Vdovin](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Andrew\_Vdovin](https://discuss.elastic.co/u/Andrew_Vdovin)\
**Post date:** [November 12, 2018, 12:50pm UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/4 "2018-11-12T12:50:12Z")

</div>

Thanks for your question. Yes, it is also available on Github [https://github.com/socprime/SigmaUI](https://github.com/socprime/SigmaUI)

---

<div class="post-metadata">

**Author:** ![Deus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deus/32/24724_2.png) [@Deus](https://discuss.elastic.co/u/Deus)\
**Post date:** [November 12, 2018, 9:50pm UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/5 "2018-11-12T21:50:23Z")

</div>

I think this is correct link: [https://github.com/socprime/soc\_workflow\_app\_ce](https://github.com/socprime/soc_workflow_app_ce)

---

<div class="post-metadata">

**Author:** ![Andrew\_Vdovin](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@Andrew\_Vdovin](https://discuss.elastic.co/u/Andrew_Vdovin)\
**Post date:** [November 13, 2018, 6:12am UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/6 "2018-11-13T06:12:17Z")

</div>

Yes, thanks, corrected

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2018, 6:19am UTC](https://discuss.elastic.co/t/soc-workflow-app-community-edition-for-elk-stack/155184/7 "2018-12-11T06:19:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
