This project simulates a real-world intrusion scenario inside a controlled virtual lab using VMware, Windows Server 2022, Windows 11, Kali Linux, Sysmon, and Splunk/Wazuh.
Build a complete SOC-style environment to learn log analysis, threat detection, incident response, and MITRE ATT&CK mapping.
- VMware Workstation / ESXi
- Windows Server 2022 (Domain Controller)
- Windows 11 Endpoint
- Kali Linux (Attacker)
- Splunk or Wazuh SIEM
- Sysmon
- PowerShell
- MITRE ATT&CK Framework
- Full IR Report
- Detection Rules (Splunk, Sysmon)
- Timeline Analysis
- SOC Dashboards
- Architecture Diagrams
- T1059 PowerShell
- T1078 Valid Accounts
- T1021 Remote Services
- T1055 Process Injection
- T1086 Command Execution
- T1110 Brute Force
Eyouel Melaku