Adedipetobi/Home-SOC-Lab

GitHub: Adedipetobi/Home-SOC-Lab

一个基于 Splunk、Sysmon 和 Windows 事件日志的家庭安全运营中心实验室,用于模拟攻击检测与事件响应的端到端实操练习。

Stars: 0 | Forks: 0

# 家庭 SOC 实验室 ## 目标 本项目展示了使用 Splunk Enterprise、Sysmon 和 Windows Event Logs 设计和实现家庭安全运营中心(SOC)的过程。 目标是模拟真实的网络攻击,收集终端日志,检测恶意活动,调查安全事件,并使用行业标准的工具和技术记录发现结果。 ## 技术 - Splunk Enterprise - Sysmon - Windows 11 ARM - Kali Linux ARM - VMware Fusion Pro ## 展示技能 - SIEM - Windows Event Logs - 日志分析 - 威胁检测 - 事件响应 - MITRE ATT&CK - PowerShell 调查 - 暴力破解检测 ## 项目路线图 - [ ] 安装 VMware Fusion Pro - [ ] 创建 Windows 11 ARM 虚拟机 - [ ] 创建 Kali Linux ARM 虚拟机 - [ ] 安装 Splunk Enterprise - [ ] 安装 Sysmon - [ ] 配置 Windows Event Forwarding - [ ] 模拟暴力破解攻击 - [ ] 在 Splunk 中检测攻击 - [ ] 创建 Dashboard - [ ] 编写事件报告 - [ ] 映射到 MITRE ATT&CK ## 状态 🚧 进行中
标签:AI合规, AMSI绕过, Sysmon, 威胁检测, 安全信息与事件管理(SIEM), 安全运营中心(SOC), 库, 应急响应