FlagshipIn progress
SOC Home Lab: end-to-end detection pipeline
A full attack-to-investigation chain I can replay on demand: a simulated attacker on an isolated VLAN, a monitored target, log shipping into a SIEM, saved detections, and a written investigation for each alert that fires.
- 01Attacker
- 02Network
- 03Target
- 04Logs
- 05SIEM
- 06Detection
- 07Investigation
pfSenseSplunkKaliUbuntu ServerSigma
The full build log for this project is still being written up.