SOC Detection Lab using Elastic Stack
Technologies: Elasticsearch, Kibana, Winlogbeat, Sysmon, VMware, Kali Linux, Windows 11, Ubuntu
- Built a SOC home lab with three virtual machines (Kali Linux, Windows 11, and Ubuntu hosting the Elastic Stack).
- Configured Sysmon and Winlogbeat to collect and forward Windows security logs to Elasticsearch for centralized monitoring.
- Simulated cyber attacks from Kali Linux across multiple phases of the Cyber Kill Chain and analyzed attack traces in Kibana.
- Created dashboards and investigated security events using Windows Event Logs and Sysmon telemetry.
- Documented attack scenarios and detection techniques from a Blue Team perspective.