This project demonstrates the design, deployment, and operation of a Security Information and Event Management (SIEM) environment using Wazuh.
The lab consists of:
- Wazuh Manager, Indexer, and Dashboard
- Windows 11 endpoint with Sysmon
- Ubuntu endpoint with Auditd
- Kali Linux attack workstation
The project focuses on telemetry engineering, detection development, attack simulation, threat hunting, and incident response aligned with the MITRE ATT&CK framework.
- Wazuh
- Windows 11
- Ubuntu 20.04
- Kali Linux
- Sysmon
- Auditd
- MITRE ATT&CK
- Nmap
- Hydra
- SMBClient
- NetExec
- Designed the virtual SOC lab architecture
- Created host and asset inventories
- Documented logging architecture and data flows
- Established network segmentation and communication paths
- Deployed Wazuh Manager, Indexer, and Dashboard
- Configured Windows and Ubuntu endpoints
- Enrolled and validated Wazuh agents
- Verified secure agent-to-manager communication
- Confirmed end-to-end log ingestion
- Deployed Microsoft Sysmon
- Enabled process creation monitoring
- Configured registry activity monitoring
- Enhanced endpoint visibility through Sysmon telemetry
- Deployed Auditd
- Enabled user activity auditing
- Configured monitoring of sensitive system files
- Monitored file creation events
- Monitored file modification events
- Monitored file deletion events
Successfully collected, centralized, and analyzed Windows and Linux security telemetry through the Wazuh platform.
Develop, validate, and investigate security detections within the Wazuh SIEM environment.
- Account Discovery Detection
- PowerShell Activity Detection
- Failed Authentication Detection
- Suspicious Script Creation Detection
- Executable File Drop Detection
- Custom PowerShell Detection Rule
- Detection Engineering
- SIEM Administration
- Alert Investigation and Analysis
- Custom Rule Development
- MITRE ATT&CK Mapping
- Security Monitoring and Validation
- Nmap Reconnaissance
- Failed Login Attack Simulation
- SMB Enumeration
- SSH Brute Force Attack
- Sensitive File Access Monitoring
- Privilege Escalation Enumeration
- Alert Triage
- Threat Hunting
- Security Event Analysis
- Incident Investigation
- Root Cause Analysis
- Incident Reporting
- T1595 – Active Scanning
- T1046 – Network Service Discovery
- T1110 – Brute Force
- T1135 – Network Share Discovery
- T1005 – Data from Local System
- T1083 – File and Directory Discovery
- T1087 – Account Discovery
- T1069 – Permission Groups Discovery
Successfully generated, detected, investigated, and documented simulated attack activity across Windows and Linux endpoints.
Evaluate detection effectiveness, perform threat hunting activities, analyze alert quality, and assess overall visibility within the Wazuh SIEM environment.
- Threat Hunting Across Windows and Linux Endpoints
- Detection Validation and Review
- MITRE ATT&CK Coverage Analysis
- False Positive Analysis
- Detection Tuning and Optimization
- Threat Hunting Report
- MITRE ATT&CK Coverage Matrix
- False Positive Analysis Report
- Detection Tuning Report
Validated visibility into simulated attacker activity, assessed detection coverage, and identified opportunities for future detection improvements and tuning.