Null the noise.
Your entire SOC,
one platform.
NullSOC unifies detection, investigation, response and compliance in a single product. A ClickHouse core, a Wazuh compatible rules engine, and no per agent license tax. Run it yourself or let us run it for you.
Live overview. Detection, threat activity and response, one screen.
From raw log to signed report,
without leaving the product.
Five stages, one data path. Each stage is inspectable, each is yours to tune, and every finding keeps a trace back to the exact line that produced it.
Twelve pillars. Every one built,
not on a roadmap.
Each pillar is a complete product surface with its own dashboards, editors and reports. Open any one for the full detail.
Detection and rules engine
A Wazuh compatible parent trigger cascade over 4,512 rules and 764 decoders, with multi step correlation and a live backtest on real history before you enable anything.
Log management and Discover
Search every decoded field with no index planning. Filters, histogram, column pills, row expansion, and saved views that become dashboard tiles or scheduled reports.
Dashboards and analytics
25 chart types from area and stacked stream to Sankey, treemap, choropleth and ATT&CK heatmap. Drag and drop canvas, nested sub tabs, and a YAML editor for the same chart.
Threat hunting and MITRE ATT&CK
A purpose built hunting surface across authentication, endpoint and network, with the ATT&CK matrix lit by your own detections and a pivot straight into the raw events.
Endpoint security
File integrity with before and after hashes, CIS configuration assessment, vulnerability lifecycle from five live feeds, IT hygiene inventory and malware detection, per agent.
Incident management
Issue style cases with comments, history, observables, tasks and attachments. SLA enforcement escalates on its own, and cases link or merge without losing a thread.
SOAR, playbooks and automation
Workflows as YAML, not a canvas you cannot diff. Finding, webhook, schedule and manual triggers, 21 credential types, human approval steps and a full run inspector.
Alerting and notifications
Triggers written in the same condition grammar as the rules. Multi field dedup windows stop repeat storms, then one delivery per channel: email, Slack, Teams, Telegram, webhook.
Threat intelligence
45.9 million indicators from 16 feeds, matched against every decoded event by address, domain, URL and file hash. Bloom filtered for speed, deduplicated so one beacon is one alert.
Compliance
PCI DSS, NIST 800-53, HIPAA, GDPR, TSC and GPG13, each mapped from the rules that fired. Per control coverage, per host posture, and a framework report you can hand to an auditor.
Reporting
Print first A4 reports across 13 pillars, built from the same live queries the pages draw. PDF for the summary, Excel for the data, delivered on a cron you set, to the channel you pick.
Administration, RBAC and operations
Four roles with per module read, write and delete. SAML and OIDC single sign on, API tokens, a full audit log, editable retention per table, and a pipeline health view that names what broke.
A modern stack, and only
one port facing the internet.
Columnar storage instead of an inverted index. A streaming collector instead of a heavyweight forwarder. Everything else stays on your private network.
Three ways to run it.
Same platform in all three.
No feature is held back for a higher tier. The difference is who operates it.
Self hosted
Your infrastructure, your data, your network. One compose stack on a single host, or split across nodes as you grow.
- ✓ Data never leaves your estate
- ✓ Docker compose, one command deploy
- ✓ Air gap friendly, feeds can be mirrored
- ✓ Full source access to your detection content
NullSOC Cloud
We run the platform, you run the SOC. Upgrades, feeds, storage and scaling are handled. You keep every admin control.
- ✓ Provisioned and upgraded for you
- ✓ Threat intel feeds always current
- ✓ Regional data residency
- ✓ Same RBAC, SSO and audit as self hosted
Fully managed
The platform plus the analysts. Codesecure operates NullSOC on your behalf, triaging and responding around the clock.
- ✓ 24x7 monitoring and triage
- ✓ Detection content tuned to your estate
- ✓ Incident response on retainer
- ✓ You keep full read access to everything
The SOC stack, rebuilt
without the tax.
- × A SIEM, a case tool, a SOAR and a report generator, each with its own login and its own idea of what an event is
- × Billing that rises with every agent and every gigabyte, so the honest answer to "should we log this" becomes no
- × Detection content locked in a vendor format you cannot read, diff or take with you
- × Alert volume treated as a feature, tuning treated as a professional services engagement
- ✓ One product, one data model, one login. A finding, a case and a report are the same object seen three ways
- ✓ Priced by platform. Onboard every endpoint and log every source without a procurement conversation
- ✓ Rules, decoders, correlations and playbooks are YAML you can read, edit, version and export
- ✓ Dedup, correlation and severity gating built into the engine, so noise is the default thing to remove
An open foundation, not a fork you cannot leave
The rules engine speaks the Wazuh ruleset, so thousands of community detections import and run unchanged. Your own content is YAML in the same grammar. If you ever leave, you leave with it.
No per agent, per GB license tax
Volume based pricing quietly shapes security decisions: teams stop logging the noisy source that turns out to matter. NullSOC prices the platform, so coverage is an engineering decision again.
All in one, and actually finished
Cases, SLA, playbooks, alerting, compliance and designed reports are in the product today, not on a slide. Twelve pillars, each with its own dashboards, editors, exports and audit trail.
A modern stack under the hood
ClickHouse for columnar analytics, Vector for ingest, a worker per concern and a browser client that never waits on a cluster. Adding a field costs nothing. Adding a source costs a decoder.
See it properly before
you talk to anyone.
Guided product tour
Forty five minutes with an engineer, against real data, on the pillars that matter to your estate. No slides.
Deployment guide
The compose stack, sizing guidance, retention planning, and how to bring your existing Wazuh content across.
How detection works
The cascade, the condition grammar, correlation, threat intel matching, and how to backtest a rule on real history.
Reach a security engineer,
not a contact form queue.
NullSOC is built and supported by Codesecure Solutions, an independent security firm in Chennai. Scoping questions, an RFP, an NDA or a quick technical answer, any of these routes gets to the same team.
Velachery, Chennai, Tamil Nadu 600042, India
Bring your noisiest source.
We will null it on the call.
Show us the log source you stopped collecting because it was too expensive or too loud. We will ingest it, decode it, and show you what is actually in there.
Powered by Codesecure Solutions. Self hosted, cloud or fully managed.
