Enterprise SIEM lab using Elastic Stack for a dedicated SOC server, ingest endpoint logs, simulate different attack techniques, and create custom detection rules mapped to MITRE ATT&CK for real-world alert investigation.
Read LabI built a Wazuh SIEM in Docker on my Mac (ARM64), added a Linux endpoint with the agent, and walked through generating real alerts.
Read LabContainer-based home lab on Raspberry Pi with Docker and Portainer—a secure, reproducible base for SIEMs, honeypots, IDS, and monitoring.
Read LabBroad SOC training focused on blue team fundamentals, core defensive tooling, alert triage, phishing analysis, and practical network/security monitoring skills.
View Full DetailsBroad SOC analyst training centered on incident handling fundamentals, ATT&CK-aligned detection, SIEM investigation, threat hunting, and hands-on defensive analysis.
View Full Details