SOC Detection Lab using Elastic Stack
Technologies: Elasticsearch, Kibana, Winlogbeat, Sysmon, VMware, Kali Linux, Windows 11, Ubuntu
- Built a SOC home lab with three virtual machines (Kali Linux, Windows 11, and Ubuntu hosting the Elastic Stack).
- Configured Sysmon and Winlogbeat to collect and forward Windows security logs to Elasticsearch for centralized monitoring.
- Simulated an RDP brute-force attack from Kali Linux and validated end-to-end detection in Kibana.
- Built dashboards visualizing both baseline system activity and live attack detection.
- Documenting each phase from a Blue Team perspective — log collection, attack simulation, and (in progress) detection alerting.