Skip to content

Repository files navigation

SOC-Lab

I am creating this SOC-Lab to learn how to draw logical diagrams, setup and configure Elastic Logstash and Kibana (ELK), attack detect and investigate, create alerts and dashboards, setup and integrate a ticketing system.

What I built:

Elastic Stack / Kibana

Fleet Server + Elastic Agents

Windows Server telemetry with Sysmon

Linux SSH honeypot

RDP/SSH attack simulations

Detection rules and dashboards

Mythic C2 / Apollo attack simulation

osTicket alert integration

Elastic Defend automated host isolation

Lab Progression

A chronological record of the lab's development, from the initial Elastic infrastructure through attack simulation, telemetry investigation, ticketing, and automated response.

Day Description
Day 1 Designed the initial SOC lab architecture and network layout.
Day 2 Deployed the initial Elastic Stack infrastructure and configured Elasticsearch.
Day 3 Configured Kibana and secured the Elastic environment.
Day 4 Added the Windows attack target and established the endpoint architecture.
Day 5 Deployed Fleet Server and enrolled the Windows endpoint.
Day 6 Installed and configured Sysmon for Windows endpoint telemetry.
Day 7 Added Windows event log integrations and began collecting security telemetry.
Day 8 Deployed the Linux SSH honeypot and collected authentication telemetry.
Day 9 Created dashboards for SSH authentication activity and investigated the collected data.
Day 10 Created and tested brute-force detection rules for SSH and RDP activity.
Day 11 Expanded authentication dashboards and investigated successful and failed RDP/SSH activity.
Day 12 Designed the attack scenario and mapped the planned Windows RDP/C2 attack into multiple phases.
Day 13 Deployed Kali Linux and Mythic infrastructure for controlled attack simulation.
Day 14 Simulated an attack against the Windows server using RDP brute force and a Mythic Apollo C2 agent.
Day 15 Investigated telemetry generated by the Apollo attack, added dashboards, integrated osTicket, and tested automated host isolation with Elastic Defend.

TO VIEW THE PROGRESS PLEASE OPEN THE MARKDOWN FILES NAMED DayN.md

About

I am creating this SOC-Lab to learn how to draw logical diagrams, setup and configure Elastic Logstash and Kibana (ELK), attack detect and investigate, create alerts and dashboards, setup and integrate a ticketing system. I will be using this person's tutorial playlist to do so.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors