Manojkumarbp/purple-Team-Lab
GitHub: Manojkumarbp/purple-Team-Lab
一个企业级紫队安全实验室,通过模拟真实 AD 域环境结合 Splunk SIEM 平台,帮助安全从业者实践事件响应、威胁狩猎与检测工程。
Stars: 0 | Forks: 0
# 🛡️ 企业级 Purple Team 实验室
## 概述
本仓库记录了我个人构建的企业级 Purple Team 实验室,旨在加强以下方面的实践技能:
- 安全运营中心 (SOC)
- 事件响应
- 威胁狩猎
- 检测工程
- Windows 安全监控
- Active Directory 安全
## 实验室架构
### 虚拟机
| 机器 | 角色 | IP |
|----------|------|-------------|
| Kali Linux | 攻击者 | 192.168.xxx.xxx |
| Windows Server 2022 | 域控 (DC01) | 192.168.xxx.xxx|
| Windows 11 | 加入域的终端 | 192.168.xxx.xxx |
## 技术栈
- VMware Workstation
- Active Directory
- Windows Server 2022
- Windows 11
- Kali Linux
- Splunk Enterprise
- Splunk Universal Forwarder
- Sysmon (SwiftOnSecurity 配置)
## 学习目标
- 事件响应
- 威胁狩猎
- 检测工程
- Windows 事件分析
- MITRE ATT&CK 映射
- Splunk 检测开发
## 仓库结构
```
Architecture/
Active-Directory/
Splunk/
Sysmon/
Investigations/
Detection-Rules/
Threat-Hunting/
Incident-Reports/
MITRE-ATTACK/
Screenshots/
```
## 状态
🚧 正在进行中
随着我完成新的调查、构建检测规则并改进我的 Purple Team 实验室,本仓库会持续更新。
标签:Active Directory, Plaso, SOC分析, Terraform 安全, 库, 应急响应, 管理员页面发现, 紫队