Codesecure SolutionsA Codesecure Solutions product
Unified SOC platform

Null the noise. Your entire SOC,
one platform.

NullSOC unifies detection, investigation, response and compliance in a single product. A ClickHouse core, a Wazuh compatible rules engine, and no per agent license tax. Run it yourself or let us run it for you.

4,500+ rules, enabled on day one 45.9M threat intel indicators Self hosted or SaaS
Powered by Codesecure Solutions
nullsoc.in / overview
The NullSOC overview: detection, threat activity and response KPI bands over live data, with detections stacked by severity.

Live overview. Detection, threat activity and response, one screen.

The null pipeline Everything arrives. Almost nothing should reach an analyst. This is where the rest goes.
Ingest raw events from every source Decode normalized to ECS, enriched Detect the rule cascade fires Correlate multi step patterns confirm Alert what an analyst actually sees
One platform
Twelve pillars, one product
Detection through compliance in a single interface. No stitching four tools together.
Open foundation
Your content stays yours
Wazuh compatible rules and decoders, authored in readable YAML. Nothing is a black box.
Built for log scale
ClickHouse at the core
Columnar storage and Vector ingest. Tens of millions of events, queried from the browser.
No license tax
Priced by platform, not agent
Add every endpoint you own. The bill does not move with your estate or your ingest volume.
One platform

From raw log to signed report,
without leaving the product.

Five stages, one data path. Each stage is inspectable, each is yours to tune, and every finding keeps a trace back to the exact line that produced it.

01
Ingest
Vector collects agent, syslog, file and cloud sources straight into ClickHouse. Drop junk before it lands.
agentssyslogcloudingest filters
02
Decode
764 decoders normalize every source to ECS field names, then GeoIP and asset context are attached.
ECS normalizeGeoIP and ASNfield groupsenrichment
03
Detect
A 4,512 rule cascade, multi step correlation and 45.9M indicator threat intel matching, all in line.
rule cascadecorrelationIOC matchingbacktest
04
Investigate
Discover any field, build dashboards from 25 chart types, hunt across the estate, pivot through ATT&CK.
Discoverdashboardsthreat huntingMITRE ATT&CK
05
Respond
Cases with SLA, YAML playbooks, alert routing to any channel, and designed PDF or Excel reports on a schedule.
cases and SLAplaybooksalertingreporting
The platform, in full

Twelve pillars. Every one built,
not on a roadmap.

Each pillar is a complete product surface with its own dashboards, editors and reports. Open any one for the full detail.

Detection and rules engine

A Wazuh compatible parent trigger cascade over 4,512 rules and 764 decoders, with multi step correlation and a live backtest on real history before you enable anything.

cascade · decoders · correlationExplore

Log management and Discover

Search every decoded field with no index planning. Filters, histogram, column pills, row expansion, and saved views that become dashboard tiles or scheduled reports.

search · filters · saved viewsExplore

Dashboards and analytics

25 chart types from area and stacked stream to Sankey, treemap, choropleth and ATT&CK heatmap. Drag and drop canvas, nested sub tabs, and a YAML editor for the same chart.

25 chart types · canvasExplore

Threat hunting and MITRE ATT&CK

A purpose built hunting surface across authentication, endpoint and network, with the ATT&CK matrix lit by your own detections and a pivot straight into the raw events.

hunting · ATT&CK matrixExplore

Endpoint security

File integrity with before and after hashes, CIS configuration assessment, vulnerability lifecycle from five live feeds, IT hygiene inventory and malware detection, per agent.

FIM · SCA · vulns · hygieneExplore

Incident management

Issue style cases with comments, history, observables, tasks and attachments. SLA enforcement escalates on its own, and cases link or merge without losing a thread.

cases · SLA · observablesExplore

SOAR, playbooks and automation

Workflows as YAML, not a canvas you cannot diff. Finding, webhook, schedule and manual triggers, 21 credential types, human approval steps and a full run inspector.

workflows · connectors · approvalsExplore

Alerting and notifications

Triggers written in the same condition grammar as the rules. Multi field dedup windows stop repeat storms, then one delivery per channel: email, Slack, Teams, Telegram, webhook.

match · dedup · channelsExplore

Threat intelligence

45.9 million indicators from 16 feeds, matched against every decoded event by address, domain, URL and file hash. Bloom filtered for speed, deduplicated so one beacon is one alert.

16 feeds · IOC matchingExplore

Compliance

PCI DSS, NIST 800-53, HIPAA, GDPR, TSC and GPG13, each mapped from the rules that fired. Per control coverage, per host posture, and a framework report you can hand to an auditor.

6 frameworks · per controlExplore

Reporting

Print first A4 reports across 13 pillars, built from the same live queries the pages draw. PDF for the summary, Excel for the data, delivered on a cron you set, to the channel you pick.

13 reports · PDF and ExcelExplore

Administration, RBAC and operations

Four roles with per module read, write and delete. SAML and OIDC single sign on, API tokens, a full audit log, editable retention per table, and a pipeline health view that names what broke.

RBAC · SSO · audit · healthExplore
Architecture

A modern stack, and only
one port facing the internet.

Columnar storage instead of an inverted index. A streaming collector instead of a heavyweight forwarder. Everything else stays on your private network.

Sources
Endpoint agents windows, linux
Syslog and files 514, tail
Cloud and SaaS api pull
Network and WAF json, text
Ingest
Vector collector
Ingest filters drop pre store
Trace id stamped at the door
Back pressure safe disk buffer
Core
ClickHouse columnar
Detection worker decode, rules
Feed worker geo, intel
Report worker pdf, xlsx
Access
Web application 443 only
Session and RBAC per module
SAML and OIDC sso
Outbound channels smtp, http
COLLECT → STORE → DECODE → DETECT → PRESENT
One public surface Only the web application is reachable. The database, the workers and the collector never leave the private network.
Storage you control Retention is a setting per table, not a support ticket. Raw events, decoded events and findings each age out on their own schedule.
No index planning ClickHouse stores columns, so a new field costs nothing and a query over a hundred million rows still returns while you are looking at it.
Deployment

Three ways to run it.
Same platform in all three.

No feature is held back for a higher tier. The difference is who operates it.

Option one

Self hosted

Your infrastructure, your data, your network. One compose stack on a single host, or split across nodes as you grow.

  • Data never leaves your estate
  • Docker compose, one command deploy
  • Air gap friendly, feeds can be mirrored
  • Full source access to your detection content
Talk to us
Option three

Fully managed

The platform plus the analysts. Codesecure operates NullSOC on your behalf, triaging and responding around the clock.

  • 24x7 monitoring and triage
  • Detection content tuned to your estate
  • Incident response on retainer
  • You keep full read access to everything
Talk to us
Why NullSOC

The SOC stack, rebuilt
without the tax.

The usual arrangement
  • × A SIEM, a case tool, a SOAR and a report generator, each with its own login and its own idea of what an event is
  • × Billing that rises with every agent and every gigabyte, so the honest answer to "should we log this" becomes no
  • × Detection content locked in a vendor format you cannot read, diff or take with you
  • × Alert volume treated as a feature, tuning treated as a professional services engagement
NullSOC
  • One product, one data model, one login. A finding, a case and a report are the same object seen three ways
  • Priced by platform. Onboard every endpoint and log every source without a procurement conversation
  • Rules, decoders, correlations and playbooks are YAML you can read, edit, version and export
  • Dedup, correlation and severity gating built into the engine, so noise is the default thing to remove
01

An open foundation, not a fork you cannot leave

The rules engine speaks the Wazuh ruleset, so thousands of community detections import and run unchanged. Your own content is YAML in the same grammar. If you ever leave, you leave with it.

02

No per agent, per GB license tax

Volume based pricing quietly shapes security decisions: teams stop logging the noisy source that turns out to matter. NullSOC prices the platform, so coverage is an engineering decision again.

03

All in one, and actually finished

Cases, SLA, playbooks, alerting, compliance and designed reports are in the product today, not on a slide. Twelve pillars, each with its own dashboards, editors, exports and audit trail.

04

A modern stack under the hood

ClickHouse for columnar analytics, Vector for ingest, a worker per concern and a browser client that never waits on a cluster. Adding a field costs nothing. Adding a source costs a decoder.

Talk to us

Reach a security engineer,
not a contact form queue.

NullSOC is built and supported by Codesecure Solutions, an independent security firm in Chennai. Scoping questions, an RFP, an NDA or a quick technical answer, any of these routes gets to the same team.

Get started

Bring your noisiest source.
We will null it on the call.

Show us the log source you stopped collecting because it was too expensive or too loud. We will ingest it, decode it, and show you what is actually in there.

Powered by Codesecure Solutions. Self hosted, cloud or fully managed.