soc-lab
Here are 15 public repositories matching this topic...
A set of Windows tools designed for SOC labs and controlled test environments providing automated TLS key logging setup for web encrypted traffic analysis and enabling or disabling of 16 Windows Defender components (9 functional protection components and 7 services/drivers) to support malware research, detection engineering, and Blue Team training.
-
Updated
Jan 11, 2026
SOC monitoring lab built using Graylog, OpenSearch, and Ubuntu. Includes log ingestion, detection engineering, alerting, and dashboards.
-
Updated
Mar 5, 2026
ICMP Protocol Analysis Lab using Wireshark – A hands-on cybersecurity lab focused on capturing and analyzing ICMP Echo Request and Reply packets, interpreting protocol fields, and applying Wireshark filters for investigation.
-
Updated
Apr 16, 2025
A hands-on Azure Cybersecurity lab focused on monitoring real-time RDP brute-force attacks using Windows Event Viewer and Geolocation tracking.
-
Updated
Feb 10, 2026
End-to-end attack detection lab using Wazuh SIEM, Sysmon, and Windows event log analysis with MITRE ATT&CK mapping.
-
Updated
Mar 5, 2026
-
Updated
Feb 27, 2026
Your full Guideline on how to install, deploy and use the Wazuh SIEM tool for newbies.
-
Updated
Feb 23, 2026
SIEM-based SOC lab with real investigations, telemetry, and detection use cases across Windows & Linux
-
Updated
Mar 15, 2026
Wazuh SIEM Implementation for Security Monitoring
-
Updated
Mar 18, 2026
SOC Alert Triage Lab – Simulated SOC alert classification and triage using Python.
-
Updated
Mar 13, 2026 - Python
PowerShell attack simulation and SOC detection analysis using Wazuh and Sysmon (MITRE ATT&CK Mapping).
-
Updated
Mar 18, 2026
Improve this page
Add a description, image, and links to the soc-lab topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the soc-lab topic, visit your repo's landing page and select "manage topics."