Building a Home SOC Lab
dev.to·1d·
Discuss: DEV
🌐Network Security
Preview
Report Post

In this project, I built a complete Security Operations Center (SOC) home lab to simulate real-world cyberattacks and monitor them in real-time. This lab demonstrates how to identify an attacker’s origin, map behaviors to the MITRE ATT&CK framework, and implement proactive detection using Auditd.

The Architecture

I used Proxmox to host my virtual environment, consisting of three primary machines:

  • Wazuh Manager (Ubuntu): The central nervous system for log collection and analysis.
  • Attacker (Kali Linux): Used to launch automated brute-force attacks.
  • Victim (Debian): The target systems monitored by Wazuh agents.

Phase 1: The Brute Force Simulation

To test the detection capabilities, I used Hydra on my Kali machine to launch a password-guessing attack against the v…

Similar Posts

Loading similar posts...