manmath1272-design/SOC-Authentication-Monitoring-Dashboard

GitHub: manmath1272-design/SOC-Authentication-Monitoring-Dashboard

基于 Splunk Enterprise 的 SOC 仪表板项目,通过采集和分析 Windows 安全事件日志实现暴力破解检测、告警与可视化监控。

Stars: 0 | Forks: 0

# 🛡️ SOC 身份验证监控仪表板

一个 Splunk Enterprise 项目,专注于监控 Windows 身份验证事件、检测暴力破解攻击、生成警报,并通过交互式 SOC 仪表板可视化安全数据。 # 📌 项目概述 本项目演示了安全运营中心 (SOC) 分析师如何使用 Splunk Enterprise 收集、分析、检测和可视化 Windows 身份验证事件。 使用 Splunk Universal Forwarder 从 Windows 11 虚拟机收集 Windows Security Event Logs,并使用 Splunk Search Processing Language (SPL) 进行分析。 # 🎯 目标 - 监控 Windows 成功登录 - 监控 Windows 失败登录 - 检测暴力破解攻击 - 生成安全警报 - 构建身份验证监控仪表板 - 提高 Windows 日志可见性 # 🏗️ 实验架构 ``` Windows 11 Virtual Machine │ ▼ Splunk Universal Forwarder │ ▼ Splunk Enterprise │ ▼ Search → Detection → Alert → Dashboard ``` # 🛠️ 使用的工具 - Splunk Enterprise - Splunk Universal Forwarder - Windows 11 - VirtualBox - Windows Security Event Logs - SPL (Search Processing Language) # 📊 使用的事件 ID | 事件 ID | 描述 | |----------|-------------| | 4624 | 成功登录 | | 4625 | 失败登录 | | 4672 | 分配特殊权限 | | 4688 | 进程创建 | # 🚨 检测逻辑 本项目通过以下方式检测暴力破解登录尝试: - 排除 SYSTEM 账户 - 排除 Service Accounts - 排除 Machine Accounts - 检测 1 分钟内 5 次或以上的失败登录尝试 # 📈 仪表板面板 - 成功登录 - 失败登录 - 暴力破解尝试 - 登录活动趋势 - 主要目标用户 - 主要源 IP 地址 - 最近的失败登录 # 🎯 MITRE ATT&CK | 技术 | 名称 | |-----------|------| | T1110 | 暴力破解 | # 📂 仓库结构 ``` SOC-Authentication-Monitoring-Dashboard │ ├── screenshots ├── dashboard_queries ├── report └── README.md ``` # 📸 截图 截图可在 **screenshots/** 文件夹中找到。 ## 📸 完整项目概述 ![项目概述](https://static.pigsec.cn/wp-content/uploads/repos/cas/1a/1a340cd601dbe234b6b56e4f4f008b9e40dbedbdf1814e99b78a05239a395927.png) ## 📊 SOC 身份验证仪表板 ![SOC 仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/34/34bba8a414325049122e16beedee38a9cb1e53a5713e5357698f70212e6a163d.png) ## 🚨 暴力破解检测 ![暴力破解检测](https://static.pigsec.cn/wp-content/uploads/repos/cas/34/34eefc739049ac82d3defd1b98a9e3ab690e54f2f5e3ed9d97c91bde8c4a007e.png) ## 🔔 触发的警报 ![触发的警报](https://static.pigsec.cn/wp-content/uploads/repos/cas/01/0179bc979e09bc1f43df99c6aa24210b24051798fb457ba69b869d3f45c57387.png) # 📝 SPL 查询 本项目中使用的所有查询均可在以下位置找到: ``` dashboard_queries/dashboard_queries.txt ``` # 💡 展现的技能 - Splunk SPL - 日志分析 - 身份验证监控 - 检测工程 - 暴力破解检测 - 警报创建 - 仪表板开发 - Windows Security Event 分析 - SOC 调查 # ⚠️ 免责声明 本项目在受控的实验环境中进行,仅用于教育和防御性网络安全目的。
标签:PB级数据处理, Windows事件监控, 免杀技术, 安全运维, 安全运营中心, 暴力破解检测, 红队行动, 网络映射