This home lab turns documentation into evidence. It combines deliberately instrumented endpoints, a segmented virtual network, and a defined attack-simulation routine so each detection can be validated against the logs it is expected to produce.
Project signal
4 zones
identity, user, server, analyst
Core stack
Wazuh · Sysmon · Windows Event Forwarding · Ubuntu
Architecture
Windows workstations and Linux servers emit process, authentication, file, and network telemetry.
Wazuh agents, Sysmon, and network sensors forward consistently tagged events into the manager.
Dashboards and saved investigations validate use cases against atomic attack simulations.
Capabilities
Operational views
These interface snapshots define the key evidence surfaces for the project. They are intentionally designed around investigation context rather than decorative dashboards.
View 01
Windows workstations and Linux servers emit process, authentication, file, and network telemetry.
View 02
Wazuh agents, Sysmon, and network sensors forward consistently tagged events into the manager.
View 03
Dashboards and saved investigations validate use cases against atomic attack simulations.
Roadmap
Continue exploring
SOC Engineering
A detection-first SOC operations workspace that brings telemetry health, triage context, and response playbooks into one deliberate workflow.
Detection Engineering
A practical rule-development workflow that connects hypotheses, sample telemetry, test cases, and release decisions.
Threat Hunting
A hypothesis-led investigation framework for turning ATT&CK-informed questions into repeatable hunts and measurable improvements.