SOC / SIEM Detection Lab
A home SOC environment for endpoint telemetry, security monitoring, and investigating suspicious behavior.
Lab
- Technologies
- Windows, Sysmon, Splunk/Wazuh
- Source code
- GitHub link to be added
Simulated preview · temporary illustration, not project evidence.
Overview
I built a home SOC environment to collect endpoint telemetry, simulate malicious activity, and investigate logs, alerts, and suspicious behavior.
What I worked on
- Centralized Windows and Sysmon security events.
- Performed SIEM monitoring, detection, investigation, and analysis.
- Used Windows, Sysmon, and Splunk/Wazuh in the lab environment.
Further documentation
Screenshots, specific detection examples, configuration notes, and a repository link will be added here. No performance metrics or detection results are claimed beyond the work described above.
Actual screenshots and evidence to be added.