
🔐 Cybersecurity · C4 Architecture · Pro
A SOC platform: logs and alerts flow into a SIEM, SOAR playbooks automate response, and analysts work cases.
C4 Architecture diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.
Drawing diagram…
Security operations centre architecture: log sources (EDR agents, firewalls, cloud audit logs, identity provider) send data to a log collector and the SIEM (Microsoft Sentinel / Splunk). Detection rules raise alerts; a SOAR platform runs playbooks (enrich with threat intelligence, isolate host via EDR, disable user in the IdP). Analysts investigate in a case management tool and escalate incidents.
C4Container
title Security Operations Centre
Person(analyst, "SOC Analyst", "Investigates alerts")
System_Ext(edr, "EDR Agents", "Endpoint telemetry")
System_Ext(fw, "Firewalls and Proxies", "Network logs")
System_Ext(cloud, "Cloud Audit Logs", "AWS, Azure, M365")
System_Ext(idp, "Identity Provider", "Sign-in logs")
System_Ext(ti, "Threat Intelligence Feeds", "IOCs")
System_Boundary(soc, "SOC Platform") {
Container(collector, "Log Collector", "Syslog / agents", "Normalises logs")
Container(siem, "SIEM", "Microsoft Sentinel", "Detection rules")
Container(soar, "SOAR", "Playbooks", "Automated response")
Container(cases, "Case Management", "Web app", "Incidents and evidence")
}
Rel(edr, collector, "Telemetry")
Rel(fw, collector, "Logs")
Rel(cloud, collector, "Audit logs")
Rel(idp, collector, "Sign-ins")
Rel(collector, siem, "Normalised events")
Rel(siem, soar, "Alerts")
Rel(ti, soar, "Enrichment")
Rel(soar, edr, "Isolate host")
Rel(soar, idp, "Disable user")
Rel(soar, cases, "Creates case")
Rel(analyst, cases, "Investigates")A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.