SOC Homelab
A rebuilt two-layer SOC lab, Wazuh watching the host and Suricata watching the wire, built around one question: what does network monitoring catch that host monitoring doesn't.
I work out what happened.
Cybersecurity student in Singapore. Give me a pile of logs and I'll tell you the story in them, including the parts I got wrong on the way.
I'm a cybersecurity student at the Institute of Technical Education in Singapore, and I learn by building. I care more about understanding a system than about being able to say I used it.
A rebuilt two-layer SOC lab, Wazuh watching the host and Suricata watching the wire, built around one question: what does network monitoring catch that host monitoring doesn't.
Two write-ups working through Splunk's own 33-million-event BOTSv1 training dataset as the defender, a website defacement and a ransomware outbreak on the same simulated network.
A Python tool that parses a Linux auth log once and runs four detection rules over it, then prints a ranked alert report.
My first full Hack The Box machine, taken from a guest cookie to a shell on the box.