Healthcare-Focused SOC Platform

Autonomous Security Operations for Healthcare Organizations

Pink Hat delivers a fully automated, AI-powered Security Operations Center built for the unique compliance, threat, and data protection needs of the healthcare sector.

Request a Demo → Explore Services
14+
Automated Playbooks
<2min
Mean Response Time
4-Zone
Network Segmentation
24/7
Autonomous Monitoring
Powered by
Wazuh SIEM Shuffle SOAR MISP Threat Intel DFIR-IRIS Velociraptor Suricata IDS Zeek NSM T-Pot Honeypot

End-to-end security operations,
purpose-built for healthcare

From real-time threat detection to automated incident response and regulatory compliance — Pink Hat covers the full security lifecycle.

🛡️

Threat Detection & SIEM

Continuous log ingestion and correlation across your entire healthcare infrastructure. Wazuh-powered SIEM with custom rules tuned for EHR systems, medical IoT, and Active Directory.

WazuhLog CorrelationCustom Rules

Automated Incident Response

AI-driven SOAR platform executes 14 specialized playbooks autonomously — from ransomware containment and PHI breach response to insider threat triage, all within minutes of detection.

Shuffle SOAR14 PlaybooksML-Powered
🔍

Digital Forensics & DFIR

Structured case management and forensic investigation workflows through DFIR-IRIS. Every incident is tracked, documented, and preserved for legal and compliance purposes.

DFIR-IRISVelociraptorChain of Custody
🕵️

Threat Intelligence

Real-time IOC sharing and enrichment via MISP. Threats detected in your environment are correlated against global threat intelligence feeds and sector-specific healthcare threat data.

MISPIOC SharingFeed Enrichment
🏥

Deception & Honeypot Network

T-Pot multi-honeypot infrastructure deployed in an isolated deception zone. Adversary behavior is captured and fed back into detection rules — turning attacker recon into intelligence.

T-PotHoneypotsEarly Warning
📊

Compliance & Risk Management

Automated HIPAA breach assessment, GDPR monitoring, and continuous compliance reporting. Our P05 playbook integrates LLM-powered RAG for real-time regulatory guidance.

HIPAAGDPRAudit Logs

From alert to resolution — fully automated

Pink Hat's pipeline turns raw security events into structured, documented, and resolved incidents without manual intervention.

01

Collect

Agents on endpoints, firewalls, and network devices forward logs and telemetry to Wazuh in real time.

02

Detect

ML models including LSTM, Isolation Forest, and XGBoost analyze patterns to identify anomalies and threats.

03

Correlate

Alerts are enriched with MISP threat intel and mapped to the MITRE ATT&CK framework automatically.

04

Respond

Shuffle SOAR triggers the appropriate playbook. Containment, isolation, and notification happen in under 2 minutes.

05

Document

Every action is logged in DFIR-IRIS with full chain of custody, ready for auditors and compliance teams.

99%
Playbook Automation Rate
<2min
Mean Time to Respond
14+
Specialized Playbooks
4k+
Detection Rules

14 ML-powered response playbooks

Every major healthcare threat scenario has a dedicated automated playbook. Each one uses purpose-trained machine learning models to make containment decisions in real time.

P01

Ransomware Detection & Response

LSTM + Deep Q-Network RL for real-time containment and rollback

P02

PHI Insider Threat Detection

Isolation Forest behavioral analytics on EHR access patterns

P05

HIPAA Breach Assessment

LLM/RAG-powered regulatory analysis and breach notification

P26

Clinical Workflow IR / PSRS

Patient safety risk scoring integrated with incident response

P34

Unified Deception Platform

Coordinated honeypot interaction + threat attribution engine

+9

Additional Playbooks

DDoS mitigation, lateral movement, supply chain compromise, and more

Technology Stack

Wazuh SIEM/XDRDetection engine
Shuffle SOAROrchestration
DFIR-IRISCase management
MISPThreat intelligence
VelociraptorEDR & forensics
Suricata / ZeekNetwork security
T-Pot HoneypotDeception layer
LSTM + RL + XGBoostML models
Claude AI (LLM)P31 Command agent

Infrastructure: Proxmox VE + VMware Workstation Pro · OPNsense firewalls · Active Directory (pink_hat_hc.local) · Nginx Proxy Manager · ZeroTier L2 bridging

4-zone segmented network design

Every network zone is isolated by firewall policy with strict east-west and north-south traffic controls, minimizing blast radius for any incident.

Internet / External Users DMZ ZONE OPNsense Firewall Nginx Proxy Manager ntopng / Zeek HONEYPOT ZONE T-Pot Multi-Honeypot Cowrie · Dionaea · Conpot HEALTHCARE LAN Active Directory pink_hat_hc.local SOC ZONE Wazuh SIEM/XDR Shuffle SOAR DFIR-IRIS MISP Threat Intel Velociraptor EDR P31 Command Agent Proxmox VE · VMware Workstation Pro

Built for healthcare regulatory requirements

Pink Hat is designed from the ground up to support the compliance frameworks your organization must adhere to.

⚕️

HIPAA

Automated breach detection, risk assessment, and notification workflows aligned with HIPAA Security Rule and Breach Notification Rule requirements.

🇪🇺

GDPR

Data subject monitoring, access logging, and breach reporting timelines enforced automatically across all patient data handling systems.

🔐

MITRE ATT&CK

All detections are tagged and mapped to MITRE ATT&CK tactics and techniques, providing structured threat modeling and gap analysis.

📋

Audit Logging

Immutable, tamper-evident audit logs across every zone with full chain of custody documentation for forensic and legal proceedings.

🏗️

Zero Trust Architecture

Strict network micro-segmentation, least-privilege access controls, and continuous verification across all 4 network zones.

📊

Continuous Reporting

Automated compliance dashboards and scheduled reports delivered to stakeholders with real-time posture scoring and remediation tracking.

The Pink Hat team

A 7-person multidisciplinary security engineering team, supervised by industry-experienced faculty at ESPRIT.

Project Supervisors

AG

Mr. Ali Ghorbel

Technical Supervisor

ESPRIT Engineering Faculty
NH

Mrs. Nawel Hammami

Academic Supervisor

ESPRIT Engineering Faculty
A

Adam

SOC Lead / ML Engineer
SIEM · Playbooks · AI Integration
T

Teammate 2

Network Security Engineer
OPNsense · Segmentation · IDS
T

Teammate 3

Threat Intel Analyst
MISP · ATT&CK · IOC Feeds
T

Teammate 4

DFIR Specialist
Velociraptor · Forensics · IRIS
T

Teammate 5

Infrastructure Engineer
Proxmox · VMware · AD
T

Teammate 6

Compliance Engineer
HIPAA · GDPR · Audit
T

Teammate 7

Deception Engineer
T-Pot · Honeypots · Threat Traps

Ready to secure your healthcare organization?

Whether you're evaluating SOC solutions, need a compliance assessment, or want a live demo of our automated playbooks — reach out and our team will respond within 24 hours.

📧
contact@pinkhat-soc.com
🌐
www.pinkhat-soc.com
📍
Tunis, Tunisia — Remote engagements worldwide
⏱️
Response time: within 24 hours
Message received!

Thank you for reaching out. A member of the Pink Hat team will be in touch within 24 hours.