Skip to content

SOC Home Lab Exercises: Practical Scenarios for Security Analysts

Notifications You must be signed in to change notification settings

MyatKyawKaung/SIEM-Lab

Repository files navigation

Real-World SIEM Lab: Simulating Detection and Incident Response

This project aims to establish a robust and scalable centralized log management infrastructure using verious techologies. By deploying logcollection agents across various endpoints, firewalls, and IDS/IPS devices, we will efficiently collect and aggregate security and operational logs. This centralized repository will enable comprehensive analysis, threat detection, compliance reporting, and incident response.

Lab Logical Diagram

Installation and Configuration

  • Deploy Active Directory, Splunk Server and Universal Forwarders on relevant systems.

Data Ingestion

  • Configure Universal Forwarders to collect logs from endpoints, firewalls, IDS/IPS, and other sources.

Data Analysis

  • Utilize Splunk's search processing language (SPL) to analyze logs, identify patterns, and detect anomalies.

Alerting and Reporting

  • Create custom alerts and dashboards to proactively respond to security incidents.

About

SOC Home Lab Exercises: Practical Scenarios for Security Analysts

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published