๐ฅ Roast My Pick ยท SIH26157
Supervisory Analytics Tool for SOC Assessment (SAT-SA)
National Technical Research Organisation (NTRO)
Reasonable choice. The scoreboard liked it. The scoreboard is not the one asking questions on the day.
Worth considering. A genuinely original framing that NTRO wants, but the whole demo rests on SOC data you synthesise โ invest in making that data realistic and varied in ways you did not trivially hand-encode, or the tool just rediscovers your own assumptions. Roughly 150โ340 teams are expected to go here.
The receipts
Every red flag on this statement, in full. These are the four places it bites.
Exhibit A
No public SOC alert and case dataset exists, so you synthesise it, and the tool can only reveal the capability differences you built into that synthetic data
It gets worse
Deciding which indicators genuinely reflect capability weakness requires SOC operational expertise a student team likely lacks, so your indicators may not mean what you claim
Still reading?
The demo demonstrates the method on invented organisations rather than surfacing a real finding, which limits how convincing it can be
And the finisher
This is a specialist supervisory tool, so the value is legible mainly to an NCIIPC-type judge and lands flat with a general audience
The damage report
Every score this statement earned, and what each one actually costs you.
Feasibility
3/5Buildable. Not comfortably. There is a week in here you have not planned for yet.
The analytics themselves are standard, but there is no public dataset of SOC alert and case-management records, so you must synthesise realistic SOC operational data across multiple organisations with plausible capability differences โ and the quality of that synthetic data determines whether the tool demonstrates anything meaningful.
Innovation scope
4/5There is something genuinely new here. Do not bury it under another dashboard.
Deriving organisational capability signals from operational alert and case data โ using the SOC's own workflow exhaust as evidence of its maturity โ is a genuinely novel framing, and which indicators actually reveal capability weakness is entirely open.
Clarity
4/5The ask is unambiguous, which quietly removes your favourite excuse.
The description is unusually precise about intent and boundaries โ it names the eight capability areas to assess, states that individual alerts are evidence not the target, and explicitly lists what is out of scope โ so you know exactly what to build and what not to.
Acceptance potential
3/5Middle of the pack. This statement will not win the room for you โ you will have to.
The framing is genuinely original and NTRO clearly wants it, but the entire demonstration rests on synthetic SOC data you must construct convincingly, and if the synthetic organisations differ only in ways you deliberately encoded, the tool merely rediscovers your own assumptions.
Effort
HeavyHeavy. Somebody on this team is not sleeping in week three. Pick who, on purpose.
Synthesising realistic multi-organisation SOC data, deriving the capability indicators, and building the ranking and drill-down interface is focused work, with the data synthesis a substantial part.
Demo-ability
MediumDemoable, if you rehearse it. Nobody rehearses it.
The rank-and-drill-down story is clear, but it runs on synthetic data you authored, so the demo shows the analytical approach rather than a finding from real SOC operations.
Data
None suppliedNo dataset comes with this one, so every accuracy figure you quote is a number about labels you invented.
Nothing is provided with the statement. You are sourcing, cleaning and labelling it yourself, and that work is invisible in the demo but very visible in the questions.
The demo they will have already seen
Somewhere around 150โ340 teams are heading here, and the description is doing the choosing for most of them. They will read the same brief, reach the same architecture, and build a version of the same demo you are planning. Being correct is the floor. If your five minutes could be swapped with the team before you and nobody in the room would notice, you have not picked badly โ you have built predictably, which costs exactly the same and hurts more.
What survives
The ground worth standing on when the questions start.
- The description is exceptionally precise about scope and boundaries, including an explicit out-of-scope list, so there is no ambiguity about what to build
- Using a SOC's own workflow data as evidence of its capability is a genuinely novel and defensible framing
- Positioning the tool as decision support rather than automated judgement matches the description exactly and avoids overreach
Nothing here is fatal. It is just the list of places this statement pushes back, and you now get to push there first.
The framing is a joke. The findings are not โ they are the same analysis on the statement page, and every line above is attached to a score or a fact in the record. It is one opinion with its reasoning attached, so argue with it before you trust it.