Windows Host · 32 GB RAM · VirtualBox VM 1 — SOC 192.168.56.10 Security Onion Suricata · Zeek Elastic · Kibana 16 GB RAM ✓ running VM 2 — Tools 192.168.56.20 Wazuh + ELK TheHive · Cortex MISP · Velociraptor 6 GB RAM in progress VM 3 — Victim 192.168.56.30 Windows 10 Eval Sysmon Wazuh Agent 4 GB RAM planned VM 4 — Attack 192.168.56.40 Kali Linux Atomic Red Team Nmap · Metasploit 4 GB RAM planned Host-Only Network · 192.168.56.0/24 VM 3 + VM 4 ship logs to VM 2 (Wazuh) · VM 2 forwards to VM 1 (Security Onion) complete in progress planned
Lab architecture — 4 VMs, one host-only network, logs flowing left to the SOC server

1 published · 5 upcoming

Breaking Out of the AppSec Bubble

Getting Security Onion running, debugging VirtualBox networking, and figuring out why giving a SIEM only two network adapters breaks everything.

Read post

Endpoint Visibility: Wazuh and the Windows Log Problem

Default Windows event logging is basically useless for threat hunting. What Sysmon fixes, and how to get it all into a SIEM.

Simulating Attacks and Hunting for Them

Running ATT&CK techniques against a victim VM and hunting for them across Suricata, Zeek, and Sysmon. The core detection loop.

Case Management with TheHive

Building the habit of opening a case, documenting what you found, running enrichment, and closing it properly.

Threat Intelligence with MISP

Free threat feeds, IOC enrichment, and what threat intelligence actually looks like when you set it up yourself.

Live Forensics with Velociraptor

VQL queries, live endpoint collection, and hunting for artifacts after running Atomic Red Team tests.