I am creating this SOC-Lab to learn how to draw logical diagrams, setup and configure Elastic Logstash and Kibana (ELK), attack detect and investigate, create alerts and dashboards, setup and integrate a ticketing system.
What I built:
Elastic Stack / Kibana
Fleet Server + Elastic Agents
Windows Server telemetry with Sysmon
Linux SSH honeypot
RDP/SSH attack simulations
Detection rules and dashboards
Mythic C2 / Apollo attack simulation
osTicket alert integration
Elastic Defend automated host isolation
A chronological record of the lab's development, from the initial Elastic infrastructure through attack simulation, telemetry investigation, ticketing, and automated response.
| Day | Description |
|---|---|
| Day 1 | Designed the initial SOC lab architecture and network layout. |
| Day 2 | Deployed the initial Elastic Stack infrastructure and configured Elasticsearch. |
| Day 3 | Configured Kibana and secured the Elastic environment. |
| Day 4 | Added the Windows attack target and established the endpoint architecture. |
| Day 5 | Deployed Fleet Server and enrolled the Windows endpoint. |
| Day 6 | Installed and configured Sysmon for Windows endpoint telemetry. |
| Day 7 | Added Windows event log integrations and began collecting security telemetry. |
| Day 8 | Deployed the Linux SSH honeypot and collected authentication telemetry. |
| Day 9 | Created dashboards for SSH authentication activity and investigated the collected data. |
| Day 10 | Created and tested brute-force detection rules for SSH and RDP activity. |
| Day 11 | Expanded authentication dashboards and investigated successful and failed RDP/SSH activity. |
| Day 12 | Designed the attack scenario and mapped the planned Windows RDP/C2 attack into multiple phases. |
| Day 13 | Deployed Kali Linux and Mythic infrastructure for controlled attack simulation. |
| Day 14 | Simulated an attack against the Windows server using RDP brute force and a Mythic Apollo C2 agent. |
| Day 15 | Investigated telemetry generated by the Apollo attack, added dashboards, integrated osTicket, and tested automated host isolation with Elastic Defend. |
TO VIEW THE PROGRESS PLEASE OPEN THE MARKDOWN FILES NAMED DayN.md
