SOC Lab: Building a Mini Security Operations Center for Threat Detection, Analysis, and Incident Response
This project involves building a hands-on mini Security Operations Center (SOC) home lab to simulate offensive and defensive cybersecurity tactics in a controlled environment. It mirrors real SOC workflows by simulating threat detection, analysis, and incident response.
Through continuous learning, I honed my skills in threat detection, incident response, and vulnerability assessment using modern open-source and commercial tools.
Demonstrate hands-on expertise by studying attack lifecycles, observing attack behaviors, and simulating real-time threat monitoring—starting from initial detection to log analysis. The project simulates cyber-attacks such as scans and brute-force attempts, identifies network-level malicious activities, and implements defense mechanisms.
This project provides clarity and practical knowledge required to operate in a real SOC environment.
- Ubuntu Server: Core monitoring server hosting Splunk Enterprise, Wazuh Manager, and auditd.
- Windows 10: Victim machine configured with Sysmon, Wazuh Agent, Splunk Universal Forwarder, and EvtxECmd.
- Kali Linux: Adversary machine used for controlled attacks like reconnaissance and brute-force.
- pfSense Firewall: Network traffic monitoring and control.
- Snort IDS: Network intrusion detection system forwarding alerts to Splunk.
Explore documentation in the /docs folder for setup, architecture, and lessons learned.
See Setup-Instructions.md for detailed steps to deploy the lab environment and simulate attacks.
Welcome to fork, open issues, or suggest improvements!
This project is under the MIT License.