01 · Selected Work

SOC Lab

SIEM IR ISO A.8

A virtual Security Operations Center built to practice log monitoring, alert triage, and incident response analysis designed to mirror the day-to-day workflow of a junior SOC analyst inside a controlled virtual lab environment.

Role
Analyst / Builder
Environment
Self-hosted virtual lab
Framework Mapping
ISO 27001 Annex A.8
Overview

I built this lab because most of the audit and compliance work I'd done up to that point looked at security controls from the outside reviewing policies, checking whether a control existed on paper. I wanted to understand what's actually happening on the other side of those controls, so I set up a small virtual network and ran it the way a real SOC would: generating traffic, collecting logs centrally, writing detection rules, and triaging whatever alerts came out of them.

The lab simulates a small enterprise environment a domain controller, a couple of Windows and Linux endpoints, and a perimeter being watched by a single analyst (me). Everything from initial setup to the final incident write-ups was done solo, over several weeks of evenings and weekends.

Objectives
Tools & Stack
Process

The lab was built in multiple phases. I deployed a Windows Active Directory environment with Windows and Linux endpoints, configured centralized log collection using Wazuh, enabled Sysmon and additional telemetry, created and tuned detection rules, simulated attacks from Kali Linux, and investigated each alert from detection through incident documentation.

Findings & Deliverables
Outcome & Reflection

This project strengthened my understanding of security operations by connecting governance and compliance with hands-on monitoring, detection engineering, and incident response. It improved my ability to investigate alerts, validate security controls, and relate technical evidence to ISO 27001 requirements.

Selected Work