Security lab

SOC Home Lab

Host + endpoints + log path. Rules come after that.

activeYEAR: 2026

PROBLEM

SOC theory with no place to generate an event, see a log and write a decision.

PODEJŚCIE

A rebuildable lab where event → log → alert → note actually runs.

ARCHITECTURE

  • lab host with virtualisation
  • Windows endpoint
  • Linux endpoint
  • collector / Wazuh

IMPLEMENTATION

  • host baseline
  • agents / logs
  • a few test scenarios
  • run notes

RESULT

  • a defined log path in the lab
  • a build checklist (resource on this site)
  • exercise notes, not client metrics

LESSONS

  • fewer tools, working chain
  • without notes the lab drifts

Goal

Build an environment where an L1 exercise is repeatable: event, log, decision, note. This is not a company SOC and not a case study with invented hours saved.

Status

active: the lab is being extended. Extra tools wait until the basic pipeline works.

This site’s GitHub repo is not a VM image repo — I am not pinning GitHub “for decoration”.

Start with the build checklist.

Want a similar setup?

This is a lab / concrete loop, not a slide. Tell me what you have on the table.

The inquiry is stored on the server. The operator is notified on Telegram. There is no email autoresponder.