SOC DETECTION & RESPONSE LAB
A hands-on security operations laboratory designed to simulate enterprise SOC workflows including endpoint monitoring, centralized logging, detection engineering, investigation, incident response, and security automation.

LAB STATUS
TECHNOLOGIES
OVERVIEW
This project is a private security operations laboratory created to gain practical experience with SOC workflows in a controlled environment.
The lab is being developed incrementally, starting with the SIEM foundation and expanding toward endpoint monitoring, centralized telemetry, detection engineering, investigation, response, attack simulation, and automation.
OBJECTIVES
- >Build a controlled enterprise-style SOC environment.
- >Collect security telemetry from multiple systems.
- >Develop and test security detection rules.
- >Practice alert investigation and incident response.
- >Simulate controlled security incidents.
- >Explore SOC workflow automation.
LAB ARCHITECTURE
The lab is being built using VMware as the virtualization platform. The architecture will progressively expand as additional infrastructure and security components are added.
VMware
│
┌────────┴────────┐
│ │
Wazuh Server Lab Infrastructure
│ │
│ ┌────────┼────────┐
│ │ │ │
│ AD Windows Linux
│ DC Endpoint Endpoint
│
▼
Security Telemetry
│
▼
Detection Engine
│
▼
Alert
│
▼
Investigation
│
▼
Response / SOARArchitecture will be updated as additional lab components are implemented and validated.
INFRASTRUCTURE
| COMPONENT | PURPOSE | STATUS |
|---|---|---|
| Wazuh Server | SIEM and endpoint security monitoring | ONLINE |
| Windows Server / AD | Identity and directory services | BUILDING |
| Windows Endpoint | Endpoint telemetry and security events | QUEUED |
| Linux Endpoint | Linux security telemetry | QUEUED |
| Firewall | Network boundary and traffic monitoring | QUEUED |
| Attack Simulation VM | Controlled security testing | QUEUED |
NETWORK ARCHITECTURE
Network segmentation and traffic visibility will be introduced as the lab infrastructure expands. The goal is to separate security infrastructure, servers, endpoints, and controlled attack systems while maintaining the telemetry required for detection and investigation.
INTERNET
│
▼
FIREWALL
│
┌─────────┴─────────┐
│ │
SERVER ZONE CLIENT ZONE
│ │
┌────┴────┐ ┌─────┴─────┐
│ │ │ │
AD WAZUH Windows Kali
/DNS SERVER Endpoint /AttackLOG COLLECTION
The lab will collect security telemetry from Windows, Linux, network infrastructure, and other supported sources. Collected events will provide the foundation for detection engineering and investigation.
WINDOWS
Authentication, process, PowerShell, account and security events.
LINUX
Authentication, system and security-related events.
NETWORK
Firewall and network security telemetry.
DETECTION ENGINEERING
Detection engineering will transform collected security events into actionable alerts. Detection logic will be developed, tested, tuned, and validated against controlled activity.
- >Log source analysis
- >Event normalization
- >Detection rule creation
- >Alert validation
- >False-positive analysis
- >Detection tuning
INVESTIGATION & RESPONSE
Alerts generated by the lab will be investigated using an analyst-oriented workflow covering alert triage, event analysis, indicator review, timeline reconstruction, and response actions.
DETECT
Identify suspicious activity from security telemetry.
INVESTIGATE
Analyze events, indicators, and surrounding activity.
RESPOND
Apply appropriate containment and response actions.
SOAR / AUTOMATION
Automation will be introduced to reduce repetitive SOC activities and explore automated alert enrichment, response workflows, notifications, and operational tasks.
ALERT
│
▼
ENRICHMENT
│
▼
DECISION
│
├── Manual Investigation
│
└── Automated Action
│
▼
RESPONSEATTACK SIMULATION
Controlled security activity will be generated inside the isolated lab environment to validate telemetry, detection logic, alert generation, investigation workflows, and response procedures.
CONTROLLED ACTIVITY
│
▼
TELEMETRY
│
▼
WAZUH
│
▼
DETECTION
│
▼
ALERT
│
▼
INVESTIGATION
│
▼
RESPONSEDETECTION USE CASES
Detection use cases will be added as they are implemented and validated in the lab.
TESTING & VALIDATION
DETECTION CREATED
│
▼
ACTIVITY SIMULATED
│
▼
LOG GENERATED
│
▼
ALERT TRIGGERED?
│
┌───┴───┐
│ │
YES NO
│ │
▼ ▼
VALIDATE TUNE
│ │
└───┬───┘
▼
RETESTR&D FINDINGS
This section will document practical observations, challenges, detection limitations, telemetry gaps, tuning decisions, and lessons learned during the development of the lab.
Detailed implementation information may be intentionally limited because the underlying environment is a private research lab.
FUTURE WORK
- >Expand endpoint and network telemetry.
- >Develop additional detection use cases.
- >Improve detection validation and testing.
- >Introduce automated response workflows.
- >Add threat intelligence enrichment.
- >Expand controlled attack simulations.