Home SOC Lab
Replicates the core SOC analyst workflow: ingest logs from multiple hosts, write and tune detection rules, triage alerts, and investigate incidents end-to-end. Goes beyond 'install SIEM and see alerts': custom rules written from scratch, noise tuned out, Grafana dashboards built for analyst use, and a structured investigation workflow applied to every simulated incident.
- Multi-source log ingestion: Linux syslog, auditd, auth.log; Windows Event Logs; Sysmon EIDs 1, 3, 7, 10, 11
- Custom Wazuh rules: SSH brute force (rate-based, 8 events/60s), PowerShell encoded command detection, new Linux user creation
- Attack simulation: SSH brute force via Hydra, Mimikatz renamed binary, /etc/passwd modification, encoded PowerShell
- False positive tuning: suppression rules for known admin sudo activity; threshold calibration
- Investigation workflow: triage in Kibana, pivot to full event context, correlated events, MITRE mapping
