PROBLEM
SOC theory with no place to generate an event, see a log and write a decision.
PODEJŚCIE
A rebuildable lab where event → log → alert → note actually runs.
ARCHITECTURE
- lab host with virtualisation
- Windows endpoint
- Linux endpoint
- collector / Wazuh
IMPLEMENTATION
- host baseline
- agents / logs
- a few test scenarios
- run notes
RESULT
- a defined log path in the lab
- a build checklist (resource on this site)
- exercise notes, not client metrics
LESSONS
- fewer tools, working chain
- without notes the lab drifts
Goal
Build an environment where an L1 exercise is repeatable: event, log, decision, note. This is not a company SOC and not a case study with invented hours saved.
Status
active: the lab is being extended. Extra tools wait until the basic pipeline works.
This site’s GitHub repo is not a VM image repo — I am not pinning GitHub “for decoration”.
Start with the build checklist.