Projects

Open source SOC Lab

RSankofa

ROLEFounderPythonFastAPIReactTypeScriptViteDocker Compose
threat hunting campaigns mapped to MITRE ATT&CK
8
Docker commands to deploy
3
report formats: HTML, Markdown, JSON
3
license, no subscription
MIT
01

The problem

A SOC analyst in West Africa often ends up with logs but no tool to analyze them. Commercial SIEMs cost between $5,000 and $50,000 a year, out of reach for most local IT teams and SMBs.

02

Constraints

The tool had to stay deployable without complex infrastructure or a subscription, in three Docker commands. It also had to structure the analysis process itself: a junior analyst facing raw logs often starts from a blank page, with no method. And it had to be built as a real open source project, not a showcase, with a permissive license and genuine usefulness for organizations that can't depend on foreign vendors.

03

My role

Founder and developer at Rostel High-Tech. End-to-end design and development: parsing engine, indicator-of-compromise extraction, threat hunting campaigns mapped to MITRE ATT&CK, incident report generation.

04

Key decisions

01

Hypothesis-driven analysis, not a blank page.

Rather than a simple free-text log search tool, RSankofa structures analysis around 8 threat hunting campaigns mapped to the MITRE ATT&CK framework (brute force, lateral movement, C2, exfiltration, SQL injection, persistence...). The analyst starts from a hypothesis to test, not an empty search field.

02

MIT and self-hosting over a SaaS model.

In the tradition of major open source cybersecurity tools (Nmap, Wireshark, Wazuh, YARA, Sigma), RSankofa is distributed under the MIT license, with no subscription. For African organizations, this is also a matter of digital sovereignty, not depending on foreign vendors to build internal security capability.

05

Solution

Python/FastAPI backend, React/TypeScript/Vite frontend, Docker Compose deployment. Zero-configuration multi-format parsing (Syslog, Apache/Nginx, iptables, Windows Security Events). Automatic extraction of indicators of compromise (suspicious IPs, malicious domains, MD5/SHA256 hashes, phishing emails, CVE identifiers). Incident reports exportable in three formats: interactive HTML, Markdown, JSON.

06

Evidence

Live demo and public source code on GitHub, MIT licensed. The first open source tool built and maintained by Rostel High-Tech.

07

Roadmap

Native Wazuh and Elastic connectors, and enriching MITRE hypotheses with a local language model via Ollama, with no cloud dependency.

08

Reflection

People have often asked me why a tech studio in Senegal works on cybersecurity. As if the two couldn't coexist. As if innovating in West Africa necessarily meant doing simple things, while waiting for the means to do serious ones.

I don't see it that way.

I think the context you build in shapes what you build. Our clients don't have multinational budgets. Our users don't read interfaces in English by default. And our businesses, when they get attacked, can't call an incident response firm at $500 an hour.

That's exactly why this work makes sense here, now, within these constraints.

RoxShield exists because human cybersecurity has no solution built for the French-speaking African context. RSankofa exists because a SOC analyst in Dakar or Abidjan deserves the same tools as one in Paris or London, without paying an annual subscription in dollars.

The name Sankofa comes from an Adinkra symbol. It represents a bird flying forward while looking back. In security, that's exactly what threat hunting is. But it's also, in a way, how we work: grounding ourselves in what already exists, to build what's missing.

We're not catching up. We're taking a different path.

CONTACT

Let's talk about securing your systems.

Contact me