The lab is not “have a SIEM”. The lab is walking:
event → log → detection → alert → triage → note
This is an educational lab and a portfolio write-up. It does not describe someone else’s SOC and it does not add metrics I did not measure.
Minimum
- a host with virtualisation
- Windows and Linux as sources
- a place logs meet (Wazuh, or a conscious “not yet”)
- one test event you can replay
MITRE ATT&CK mapping only helps when a concrete log covers a technique. Otherwise it is a sticker.
The build checklist lives in Resources. A paid product — if it ships — will be an extension, not a copy of that list.