A security operations center built at home: Wazuh on Docker/WSL2, Sysmon, 9 MITRE ATT&CK-mapped detections, YARA + VirusTotal auto-quarantine, safe attack simulations.
-
Updated
Oct 7, 2026 - PowerShell
A security operations center built at home: Wazuh on Docker/WSL2, Sysmon, 9 MITRE ATT&CK-mapped detections, YARA + VirusTotal auto-quarantine, safe attack simulations.
Splunk detection engineering lab: BOTSv1 attack data, custom Sysmon parsing app, and MITRE ATT&CK-mapped detections validated against real attacks.
Watchtide: home SOC lab on Wazuh SIEM, Sysmon, SQL Server and Power BI, with triage reports, case tracking and MITRE ATT&CK coverage
Sysmon Log Intelligence SOC Automation Tool 2026 Threat Hunter
Quasar 检测评估实验台:可复现、参数外置的基线样本工程 | Reproducible parameter-externalized Quasar baseline lab. Author: Chen Sen (陈森). 禁止盗卖,禁止商业用途。
Hands-on SOC analyst portfolio: translating a logistics and data reconciliation mindset into Blue Team threat triage, log analysis, and detection engineering.
Splunk SIEM home lab with three MITRE-mapped detections, a scheduled alert, and a Tier-1 triage dashboard.
Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
Practical SOC detection engineering project focused on telemetry, validation, tuning, false-positive analysis, and reproducible evidence.
SOC detection and response lab using Wazuh, custom rules, Sysmon, Suricata, investigation workflows and Active Response.
Main Sigma Rule Repository
📧 Curate threat intelligence with mailing lists and newsletters for consistent updates critical to CTI analysts, SOC teams, and security researchers.
🦆 Engage with DUCK-E, the AI voice assistant that enhances your debugging by talking back, helping you find solutions through active conversation.
Resource-constrained SOC detection lab (Wazuh SIEM + Sysmon Modular) with 7 custom MITRE ATT&CK correlation rules, validated via adversary emulation and threat hunting.
Six Microsoft Sentinel KQL detections, controlled PowerShell scenarios, and source-event-to-alert validation with reviewed evidence.
Detection-coverage analyzer for Linux/auditd, Windows/Sysmon, and macOS/Endpoint Security. Resolves shell/command actions to ATT&CK techniques, the telemetry they emit, and the detections that would fire.
Windows detection and incident response lab using Wazuh, Sysmon, MITRE ATT&CK, and custom detection rules.
One ClickFix attack, three rule formats, two SIEMs: Sigma, Elastic KQL/EQL, and Google SecOps YARA-L detections for T1204.004
A virtualised AD environment with Splunk and Sysmon logging, attacked with Atomic Red Team and detected.
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."