FirasSaud/SOC-Home-Lab

GitHub: FirasSaud/SOC-Home-Lab

基于 Splunk Enterprise 与 Sysmon 构建的 Windows SOC 家庭实验室,用于模拟真实安全运营中心的端点监控、日志分析与威胁检测。

Stars: 0 | Forks: 0

![License](https://img.shields.io/badge/License-MIT-blue.svg) ![Splunk](https://img.shields.io/badge/SIEM-Splunk-65A637) ![Sysmon](https://img.shields.io/badge/Telemetry-Sysmon-red) ![Windows](https://img.shields.io/badge/Platform-Windows%2011-0078D4) ![Status](https://img.shields.io/badge/Project-Completed-brightgreen) # 🛡️ 使用 Splunk Enterprise 的 SOC 家庭实验室 这是一个实践性的安全运营中心(SOC)家庭实验室,使用 **Splunk Enterprise**、**Sysmon** 和 **Splunk Universal Forwarder** 构建,用于 Windows 端点监控、日志分析和威胁检测。 # 📌 项目摘要 该项目通过收集 Windows 端点遥测数据并使用 Splunk Enterprise 分析安全事件,模拟了真实世界的安全运营中心(SOC)环境。 主要目标是加强以下方面的实践技能: - 安全监控 - Windows 事件分析 - 威胁检测 - 仪表板开发 - 检测工程 - SPL 查询开发 # 🏗️ 实验环境 | 组件 | 用途 | |-----------|---------| | Windows 11 虚拟机 | 端点监控 | | Kali Linux | 攻击模拟与测试 | | Sysmon | Windows 端点遥测 | | Splunk Universal Forwarder | 日志收集与转发 | | Splunk Enterprise | SIEM 平台 | # 🔍 监控仪表板 监控仪表板提供了对 Windows 端点活动的实时可见性。 ### 功能 - 总事件数 - 进程创建 - DNS 查询 - 网络连接 - 事件时间线 - 运行中的进程 - 父进程 - PowerShell 活动 - 最近的网络连接 ## 仪表板截图 ![监控仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/40/403928116bee29fbaa16b83626732e2db152dc97d176b271c1dd8a1daf0ee36c.jpg) ![监控仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/09/090075b0ac5375620e0e382abbb60290e3d691ac368c2e9a66c01ce44c43fe5e.jpg) ![监控仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/f0/f00d06363862d77fc2fe2acb30a7b815a2cf10d2476225d0c7de2afe65e6735d.jpg) ![监控仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/2b/2b081f987324e0e7b972d80650264d732ce6bfe8c584b3db0af56b9e84f10389.jpg) # 🚨 检测仪表板 开发了自定义 SPL 检测规则,以识别可疑的端点活动。 ### 检测规则 - PowerShell 执行 - 命令提示符执行 - 编码 PowerShell 检测 - 注册表持久化 - 文件创建监控 - DNS 请求 - 网络连接 - 可执行文件下载 ## 仪表板截图 ![检测仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/00/00a22cd5abdb8901be33c8af1e97b4ed0174dda6b0cb53b603ad87567eeea983.jpg) ![检测仪表板](https://raw.githubusercontent.com/FirasSaud/SOC-Home-Lab/main/detection-2.jpeg) ![检测仪表板](https://static.pigsec.cn/wp-content/uploads/repos/cas/c6/c6b67f160ced5f4852eac6737f1130cbe70dbd3950c0ce9bea535d04afdc6603.jpg) # 🛠️ 展示技能 - Splunk Enterprise - Search Processing Language (SPL) - Sysmon 配置 - Windows 事件分析 - SIEM 监控 - 威胁检测 - 仪表板开发 - 日志收集与标准化 - 蓝队基础 # 🚀 未来改进 - Windows Server 集成 - Active Directory 部署 - MITRE ATT&CK 映射 - Splunk 告警 - 威胁狩猎仪表板 - 事件响应手册 # 👨‍💻 作者 **Firas Saud** 信息技术学生 对网络安全、SOC 运营和蓝队感兴趣。
标签:AMSI绕过, Sysmon, 威胁检测, 安全实验室, 安全运营, 扫描框架, 速率限制