SOC Home Lab
Designed and built a virtual Security Operations Center environment for attack simulation, telemetry collection, detection development, and incident investigation. This lab mirrors modern enterprise telemetry pipelines: adversarial simulations conducted from Kali Linux traverse a segmented pfSense firewall into a Windows Server Active Directory domain. Host and authentication activities are captured via fine-grained Sysmon configurations and ingested into Splunk for detection creation, SPL queries, and investigative triage.
