FlagshipIn progress

SOC Home Lab: end-to-end detection pipeline

A full attack-to-investigation chain I can replay on demand: a simulated attacker on an isolated VLAN, a monitored target, log shipping into a SIEM, saved detections, and a written investigation for each alert that fires.

  1. 01Attacker
  2. 02Network
  3. 03Target
  4. 04Logs
  5. 05SIEM
  6. 06Detection
  7. 07Investigation
pfSenseSplunkKaliUbuntu ServerSigma

The full build log for this project is still being written up.