Manojkumarbp/purple-Team-Lab

GitHub: Manojkumarbp/purple-Team-Lab

一个企业级紫队安全实验室,通过模拟真实 AD 域环境结合 Splunk SIEM 平台,帮助安全从业者实践事件响应、威胁狩猎与检测工程。

Stars: 0 | Forks: 0

# 🛡️ 企业级 Purple Team 实验室 ## 概述 本仓库记录了我个人构建的企业级 Purple Team 实验室,旨在加强以下方面的实践技能: - 安全运营中心 (SOC) - 事件响应 - 威胁狩猎 - 检测工程 - Windows 安全监控 - Active Directory 安全 ## 实验室架构 ### 虚拟机 | 机器 | 角色 | IP | |----------|------|-------------| | Kali Linux | 攻击者 | 192.168.xxx.xxx | | Windows Server 2022 | 域控 (DC01) | 192.168.xxx.xxx| | Windows 11 | 加入域的终端 | 192.168.xxx.xxx | ## 技术栈 - VMware Workstation - Active Directory - Windows Server 2022 - Windows 11 - Kali Linux - Splunk Enterprise - Splunk Universal Forwarder - Sysmon (SwiftOnSecurity 配置) ## 学习目标 - 事件响应 - 威胁狩猎 - 检测工程 - Windows 事件分析 - MITRE ATT&CK 映射 - Splunk 检测开发 ## 仓库结构 ``` Architecture/ Active-Directory/ Splunk/ Sysmon/ Investigations/ Detection-Rules/ Threat-Hunting/ Incident-Reports/ MITRE-ATTACK/ Screenshots/ ``` ## 状态 🚧 正在进行中 随着我完成新的调查、构建检测规则并改进我的 Purple Team 实验室,本仓库会持续更新。
标签:Active Directory, Plaso, SOC分析, Terraform 安全, 库, 应急响应, 管理员页面发现, 紫队