Skip to content

Repository files navigation

Wazuh SIEM Homelab

Overview

This project demonstrates the design, deployment, and operation of a Security Information and Event Management (SIEM) environment using Wazuh.

The lab consists of:

  • Wazuh Manager, Indexer, and Dashboard
  • Windows 11 endpoint with Sysmon
  • Ubuntu endpoint with Auditd
  • Kali Linux attack workstation

The project focuses on telemetry engineering, detection development, attack simulation, threat hunting, and incident response aligned with the MITRE ATT&CK framework.

Technologies Used

  • Wazuh
  • Windows 11
  • Ubuntu 20.04
  • Kali Linux
  • Sysmon
  • Auditd
  • MITRE ATT&CK
  • Nmap
  • Hydra
  • SMBClient
  • NetExec

Project Status

Phase 1 – Architecture & Planning ✅

  • Designed the virtual SOC lab architecture
  • Created host and asset inventories
  • Documented logging architecture and data flows
  • Established network segmentation and communication paths

Phase 2 – Wazuh Infrastructure Deployment ✅

  • Deployed Wazuh Manager, Indexer, and Dashboard
  • Configured Windows and Ubuntu endpoints
  • Enrolled and validated Wazuh agents
  • Verified secure agent-to-manager communication
  • Confirmed end-to-end log ingestion

Phase 3 – Telemetry Engineering ✅

Windows Telemetry

  • Deployed Microsoft Sysmon
  • Enabled process creation monitoring
  • Configured registry activity monitoring
  • Enhanced endpoint visibility through Sysmon telemetry

Linux Telemetry

  • Deployed Auditd
  • Enabled user activity auditing
  • Configured monitoring of sensitive system files

File Integrity Monitoring (FIM)

  • Monitored file creation events
  • Monitored file modification events
  • Monitored file deletion events

Validation

Successfully collected, centralized, and analyzed Windows and Linux security telemetry through the Wazuh platform.


Phase 4 – Detection Engineering ✅

Objective

Develop, validate, and investigate security detections within the Wazuh SIEM environment.

Detections Implemented

  • Account Discovery Detection
  • PowerShell Activity Detection
  • Failed Authentication Detection
  • Suspicious Script Creation Detection
  • Executable File Drop Detection
  • Custom PowerShell Detection Rule

Skills Demonstrated

  • Detection Engineering
  • SIEM Administration
  • Alert Investigation and Analysis
  • Custom Rule Development
  • MITRE ATT&CK Mapping
  • Security Monitoring and Validation

Phase 5 – Attack Simulation & Incident Response ✅

Windows Attack Simulations

  • Nmap Reconnaissance
  • Failed Login Attack Simulation
  • SMB Enumeration

Linux Attack Simulations

  • SSH Brute Force Attack
  • Sensitive File Access Monitoring
  • Privilege Escalation Enumeration

Investigation Activities

  • Alert Triage
  • Threat Hunting
  • Security Event Analysis
  • Incident Investigation
  • Root Cause Analysis
  • Incident Reporting

MITRE ATT&CK Coverage

  • T1595 – Active Scanning
  • T1046 – Network Service Discovery
  • T1110 – Brute Force
  • T1135 – Network Share Discovery
  • T1005 – Data from Local System
  • T1083 – File and Directory Discovery
  • T1087 – Account Discovery
  • T1069 – Permission Groups Discovery

Validation

Successfully generated, detected, investigated, and documented simulated attack activity across Windows and Linux endpoints.


Phase 6 – Threat Hunting & Detection Optimization ✅

Objective

Evaluate detection effectiveness, perform threat hunting activities, analyze alert quality, and assess overall visibility within the Wazuh SIEM environment.

Activities Performed

  • Threat Hunting Across Windows and Linux Endpoints
  • Detection Validation and Review
  • MITRE ATT&CK Coverage Analysis
  • False Positive Analysis
  • Detection Tuning and Optimization

Deliverables

  • Threat Hunting Report
  • MITRE ATT&CK Coverage Matrix
  • False Positive Analysis Report
  • Detection Tuning Report

Outcome

Validated visibility into simulated attacker activity, assessed detection coverage, and identified opportunities for future detection improvements and tuning.

About

Enterprise-style Wazuh SIEM homelab featuring Windows & Linux monitoring, Sysmon, Auditd, custom detections, threat hunting, incident response, and MITRE ATT&CK mapping.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors