Adedipetobi/Home-SOC-Lab
GitHub: Adedipetobi/Home-SOC-Lab
一个基于 Splunk、Sysmon 和 Windows 事件日志的家庭安全运营中心实验室,用于模拟攻击检测与事件响应的端到端实操练习。
Stars: 0 | Forks: 0
# 家庭 SOC 实验室
## 目标
本项目展示了使用 Splunk Enterprise、Sysmon 和 Windows Event Logs 设计和实现家庭安全运营中心(SOC)的过程。
目标是模拟真实的网络攻击,收集终端日志,检测恶意活动,调查安全事件,并使用行业标准的工具和技术记录发现结果。
## 技术
- Splunk Enterprise
- Sysmon
- Windows 11 ARM
- Kali Linux ARM
- VMware Fusion Pro
## 展示技能
- SIEM
- Windows Event Logs
- 日志分析
- 威胁检测
- 事件响应
- MITRE ATT&CK
- PowerShell 调查
- 暴力破解检测
## 项目路线图
- [ ] 安装 VMware Fusion Pro
- [ ] 创建 Windows 11 ARM 虚拟机
- [ ] 创建 Kali Linux ARM 虚拟机
- [ ] 安装 Splunk Enterprise
- [ ] 安装 Sysmon
- [ ] 配置 Windows Event Forwarding
- [ ] 模拟暴力破解攻击
- [ ] 在 Splunk 中检测攻击
- [ ] 创建 Dashboard
- [ ] 编写事件报告
- [ ] 映射到 MITRE ATT&CK
## 状态
🚧 进行中
标签:AI合规, AMSI绕过, Sysmon, 威胁检测, 安全信息与事件管理(SIEM), 安全运营中心(SOC), 库, 应急响应