Skip to content

Jaswanth776/SOC-LAB

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

13 Commits
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ SOC Lab

This repository showcases a Security Operations Center (SOC) Lab designed to simulate a real-world enterprise security monitoring environment. The lab replicates how security teams collect, analyze, and respond to threats using centralized logging, SIEM solutions, and intrusion detection systems.

The setup consists of multiple systems including endpoints (Windows/Linux), a SIEM server, and an attacker machine, enabling realistic generation and analysis of security events. Logs from different sources are aggregated and processed to identify suspicious activities and trigger alerts.

βš”οΈ Attack Simulation

The lab includes simulation of common attack scenarios such as:

  • πŸ” Network reconnaissance (Nmap scans)
  • πŸ” Brute-force authentication attacks
  • 🚫 Unauthorized access attempts
  • βš™οΈ Suspicious process execution

These activities demonstrate how attacks are reflected in logs and how they can be detected through correlation rules and monitoring dashboards.

🎯 Key Learning Outcomes

This project focuses on building practical skills in:

  • πŸ“Š Security event monitoring
  • 🧾 Log analysis and correlation
  • 🚨 Threat detection and alerting
  • πŸ”Ž Incident investigation and response

πŸš€ Goal

Overall, this SOC Lab provides hands-on exposure to blue team operations and helps in understanding how modern SOC environments function in detecting and mitigating cyber threats.

About

Hands-on SOC lab using Wazuh SIEM, Sysmon, Suricata, and TheHive for security monitoring, detection, and incident response.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages