SOC Lab — Splunk SIEM
Production-grade SOC environment built on Splunk. Processed 18K+ security events, custom detection dashboards, correlation rules, and threat hunting queries aligned with MITRE ATT&CK.
github
Home labs, detection engineering environments, and security tooling.
Production-grade SOC environment built on Splunk. Processed 18K+ security events, custom detection dashboards, correlation rules, and threat hunting queries aligned with MITRE ATT&CK.
Full ELK stack (Elasticsearch, Logstash, Kibana) for security monitoring. OWASP Top 10 threat detection, custom Kibana dashboards, and log ingestion pipelines for web and endpoint telemetry.
Cloud-native SOC environment on Microsoft Sentinel. Automated incident response playbooks, KQL analytics rules, UEBA configuration, and threat intelligence integration on Azure.
Hands-on capstone projects from the Google Cybersecurity Professional Certificate. Covers security frameworks, incident response, network analysis, Linux hardening, SQL security, and Python automation.
Elasticsearch lab environment optimised for ARM64 architecture (Apple M2 Mac). Docker Compose setup for local security data indexing and search experimentation without x86 constraints.