CAMPAIGN / EN

SOC L1 starts with a lab, not a certificate.

Data path first. Tools second. Extra layers after that.

CAMPAIGN: soc-l1-home-lab

Problem

  • SOC theory with no place to generate an event and see it.
  • Too many tools on day one, too little documentation of the flow.
  • An alert treated as an incident because nobody wrote context down.

Solution

  • One host, two endpoints, a collector.
  • A test event generated on purpose.
  • A decision note: true / false / escalate.

Benefits

  • A repeatable L1 drill.
  • Portfolio material without invented KPI.
  • The same path as docs and blog on this site.

Scope

  • Windows and Linux as sources
  • Wazuh as lab SIEM
  • a build checklist
  • ATT&CK mapping only where the log supports it

Proof

  • Portfolio: SOC Home Lab (status active)
  • Docs: L1 overview, Windows, Linux, Wazuh
  • Resource: free checklist

Start

Free checklist on the site. A paid extension is in preparation and is not pretending to be a shop.

  • open the checklist
  • baseline the hosts
  • add rules only after that

This campaign does not sell a “ready SOC”. It leads to an exercise you can repeat. To talk through hardware limits — contact.

Talk through the lab for your hardware limits.

The checklist stays free. The form is for scope, not a paywall.

The inquiry is stored on the server. The operator is notified on Telegram. There is no email autoresponder.