./back-to-projects
/projects/soc-lab

SOC DETECTION & RESPONSE LAB

A hands-on security operations laboratory designed to simulate enterprise SOC workflows including endpoint monitoring, centralized logging, detection engineering, investigation, incident response, and security automation.

PRIVATE R&D
IN DEVELOPMENT
HOMELAB
SOC Detection and Response Lab
[01]

LAB STATUS

>initializing_security_lab_
VMware EnvironmentONLINE
Wazuh ServerONLINE
Wazuh InstallationONLINE
Active DirectoryBUILDING
Windows EndpointQUEUED
Linux EndpointQUEUED
FirewallQUEUED
Log IntegrationQUEUED
Detection EngineeringQUEUED
Attack SimulationQUEUED
SOAR / AutomationQUEUED
> LAB_BUILD_PROGRESS27%
[02]

TECHNOLOGIES

SOC
SIEM
Wazuh
Windows
Active Directory
Detection Engineering
SOAR
Security Automation
[03]

OVERVIEW

This project is a private security operations laboratory created to gain practical experience with SOC workflows in a controlled environment.

The lab is being developed incrementally, starting with the SIEM foundation and expanding toward endpoint monitoring, centralized telemetry, detection engineering, investigation, response, attack simulation, and automation.

[04]

OBJECTIVES

  • >Build a controlled enterprise-style SOC environment.
  • >Collect security telemetry from multiple systems.
  • >Develop and test security detection rules.
  • >Practice alert investigation and incident response.
  • >Simulate controlled security incidents.
  • >Explore SOC workflow automation.
[05]

LAB ARCHITECTURE

The lab is being built using VMware as the virtualization platform. The architecture will progressively expand as additional infrastructure and security components are added.

                    VMware
                       │
               ┌────────┴────────┐
               │                 │
         Wazuh Server       Lab Infrastructure
               │                 │
               │        ┌────────┼────────┐
               │        │        │        │
               │       AD     Windows   Linux
               │       DC     Endpoint  Endpoint
               │
               ▼
         Security Telemetry
               │
               ▼
         Detection Engine
               │
               ▼
              Alert
               │
               ▼
         Investigation
               │
               ▼
          Response / SOAR

Architecture will be updated as additional lab components are implemented and validated.

[06]

INFRASTRUCTURE

COMPONENTPURPOSESTATUS
Wazuh ServerSIEM and endpoint security monitoringONLINE
Windows Server / ADIdentity and directory servicesBUILDING
Windows EndpointEndpoint telemetry and security eventsQUEUED
Linux EndpointLinux security telemetryQUEUED
FirewallNetwork boundary and traffic monitoringQUEUED
Attack Simulation VMControlled security testingQUEUED
[07]

NETWORK ARCHITECTURE

Network segmentation and traffic visibility will be introduced as the lab infrastructure expands. The goal is to separate security infrastructure, servers, endpoints, and controlled attack systems while maintaining the telemetry required for detection and investigation.

                 INTERNET
                     │
                     ▼
                  FIREWALL
                     │
           ┌─────────┴─────────┐
           │                   │
       SERVER ZONE         CLIENT ZONE
           │                   │
      ┌────┴────┐        ┌─────┴─────┐
      │         │        │           │
     AD       WAZUH   Windows      Kali
    /DNS      SERVER  Endpoint    /Attack
[08]

LOG COLLECTION

The lab will collect security telemetry from Windows, Linux, network infrastructure, and other supported sources. Collected events will provide the foundation for detection engineering and investigation.

WINDOWS

Authentication, process, PowerShell, account and security events.

LINUX

Authentication, system and security-related events.

NETWORK

Firewall and network security telemetry.

[09]

DETECTION ENGINEERING

Detection engineering will transform collected security events into actionable alerts. Detection logic will be developed, tested, tuned, and validated against controlled activity.

  • >Log source analysis
  • >Event normalization
  • >Detection rule creation
  • >Alert validation
  • >False-positive analysis
  • >Detection tuning
[10]

INVESTIGATION & RESPONSE

Alerts generated by the lab will be investigated using an analyst-oriented workflow covering alert triage, event analysis, indicator review, timeline reconstruction, and response actions.

DETECT

Identify suspicious activity from security telemetry.

INVESTIGATE

Analyze events, indicators, and surrounding activity.

RESPOND

Apply appropriate containment and response actions.

[11]

SOAR / AUTOMATION

Automation will be introduced to reduce repetitive SOC activities and explore automated alert enrichment, response workflows, notifications, and operational tasks.

ALERT
  │
  ▼
ENRICHMENT
  │
  ▼
DECISION
  │
  ├── Manual Investigation
  │
  └── Automated Action
          │
          ▼
       RESPONSE
[12]

ATTACK SIMULATION

Controlled security activity will be generated inside the isolated lab environment to validate telemetry, detection logic, alert generation, investigation workflows, and response procedures.

CONTROLLED ACTIVITY
        │
        ▼
     TELEMETRY
        │
        ▼
       WAZUH
        │
        ▼
     DETECTION
        │
        ▼
       ALERT
        │
        ▼
    INVESTIGATION
        │
        ▼
      RESPONSE
[13]

DETECTION USE CASES

Detection use cases will be added as they are implemented and validated in the lab.

> DETECTION_USE_CASES: LOADING..._
[14]

TESTING & VALIDATION

DETECTION CREATED
       │
       ▼
ACTIVITY SIMULATED
       │
       ▼
LOG GENERATED
       │
       ▼
ALERT TRIGGERED?
       │
   ┌───┴───┐
   │       │
  YES      NO
   │       │
   ▼       ▼
VALIDATE  TUNE
   │       │
   └───┬───┘
       ▼
     RETEST
[15]

R&D FINDINGS

This section will document practical observations, challenges, detection limitations, telemetry gaps, tuning decisions, and lessons learned during the development of the lab.

Detailed implementation information may be intentionally limited because the underlying environment is a private research lab.

[16]

FUTURE WORK

  • >Expand endpoint and network telemetry.
  • >Develop additional detection use cases.
  • >Improve detection validation and testing.
  • >Introduce automated response workflows.
  • >Add threat intelligence enrichment.
  • >Expand controlled attack simulations.