This project demonstrates hands-on experience relevant to a SOC Analyst role
π§± Lab Architecture Host System
- 8 CPU cores
- 32 GB RAM
Virtual Machines
- Ubuntu Server β Wazuh SIEM + Suricata
- Windows 11 β Endpoint telemetry and attack simulation
- Kali Linux β Adversary simulation
π§ Tools Used
- Wazuh (SIEM, log analysis, alerting)
- Suricata (Network IDS)
- Windows Event Logs & Sysmon
π What This Lab Demonstrates
- SOC alert monitoring and triage
- Endpoint and network log analysis
- Attack simulation and detection validation
- Incident documentation and reporting
- Mapping attacker behavior to MITRE ATT&CK