Problem
- SOC theory with no place to generate an event and see it.
- Too many tools on day one, too little documentation of the flow.
- An alert treated as an incident because nobody wrote context down.
Solution
- One host, two endpoints, a collector.
- A test event generated on purpose.
- A decision note: true / false / escalate.
Benefits
- A repeatable L1 drill.
- Portfolio material without invented KPI.
- The same path as docs and blog on this site.
Scope
- Windows and Linux as sources
- Wazuh as lab SIEM
- a build checklist
- ATT&CK mapping only where the log supports it
Proof
- Portfolio: SOC Home Lab (status active)
- Docs: L1 overview, Windows, Linux, Wazuh
- Resource: free checklist
Start
Free checklist on the site. A paid extension is in preparation and is not pretending to be a shop.
- open the checklist
- baseline the hosts
- add rules only after that
This campaign does not sell a “ready SOC”. It leads to an exercise you can repeat. To talk through hardware limits — contact.