Technologies: Elastic Stack, Kibana, KQL, Linux, SIEM
This project simulates a Security Operations Center (SOC) environment using the Elastic Stack to detect, analyze, and respond to real-world attack scenarios on a Linux system.
The lab focuses on developing practical blue team skills including threat detection, log analysis, and incident response using SIEM tools.
Each incident follows a structured SOC investigation process:
- Alert identification in Kibana (SIEM)
- Log analysis using KQL queries
- Correlation of timestamps, usernames, and source IP addresses
- Identification of suspicious or malicious behavior
- Documentation of findings and recommended response actions
Tools used in this lab:
- Elastic Stack (Elasticsearch, Kibana)
- Elastic Agent
- Ubuntu Linux endpoint
- Filebeat system authentication logs
- KQL (Kibana Query Language)
Logs monitored:
- /var/log/auth.log
- /var/log/syslog
This lab demonstrates:
- SIEM log analysis
- Linux log analysis
- Authentication monitoring
- Threat detection and basic threat hunting
- Privilege escalation detection
- Brute force attack detection
- Detection rule creation using KQL
- Incident documentation
- Security investigation workflows
| Incident | Description |
|---|---|
| Incident 01 | Brute force authentication attempts detected against local user account |
| Incident 02 | Privilege escalation activity using sudo detected |
| Incident 03 | Repeated su authentication failures indicating brute-force behavior |
| Incident 04 | Unauthorized user account creation detected using useradd command |
| Incident 05 | SSH authentication failures detected indicating possible brute force attack |
All investigations include:
- Evidence screenshots
- SIEM queries
- Security analysis
- Recommended response actions
Location: /incidents/
The simulated incidents in this lab align with known adversary techniques documented in the MITRE ATT&CK framework.
| Incident | MITRE Technique | Description |
|---|---|---|
| Incident 01 | T1110 – Brute Force | Multiple authentication failures detected against a user account |
| Incident 02 | T1548 – Abuse Elevation Control Mechanism | Privilege escalation using sudo |
| Incident 03 | T1110 – Brute Force | Repeated su authentication failures indicating brute force attempts |
| Incident 04 | T1136 – Create Account | Unauthorized user account creation detected through execution of the useradd command |
| Incident 05 | T1110 – Brute Force | Multiple SSH authentication failures detected for user hacker |
Each simulated incident is categorized based on potential impact to system security.
| Incident | Severity | Reason |
|---|---|---|
| Incident 01 | Medium | Multiple authentication failures indicating possible brute force |
| Incident 02 | High | Privilege escalation using sudo grants root access |
| Incident 03 | Medium | Repeated su authentication failures suggest credential guessing |
| Incident 04 | High | Unauthorized user account creation indicates persistence attempt |
| Incident 05 | Medium | Multiple SSH authentication failures detected for user hacker indicating potential brute force activity |
Detection rules written using Kibana Query Language (KQL) to identify suspicious activity within the Elastic SIEM environment.
| Detection | KQL Query | Description |
|---|---|---|
| Brute Force Detection | event.dataset : "system.auth" AND message : ("FAILED SU" OR "authentication failure") |
Detects multiple failed authentication attempts in Linux logs |
| Privilege Escalation Detection | event.dataset : "system.auth" AND message : "sudo" |
Detects sudo usage and potential privilege escalation |
| Unauthorized User Creation Detection | process.name : "useradd" |
Detects creation of new user accounts |
| SSH Brute Force Detection | event.dataset : "system.auth" AND message : "authentication failure" |
Detects SSH authentication failures |
Location: /detections/
Security investigations include supporting evidence from Elastic SIEM dashboards.
Location: /screenshots/
Examples include:
- Authentication timelines
- Failed login events
- Root session activity
- Privilege escalation logs
Planned enhancements for this SOC lab include:
- Detection for suspicious login times (off-hours access)
- Detection for password spraying attacks across multiple accounts
- Persistence detection techniques
- Network reconnaissance detection (Nmap scanning)
- Alert rule automation and tuning within Elastic SIEM
- Expanded MITRE ATT&CK mapping across detections
The following indicators were identified during investigations:
- Repeated failed authentication attempts from a single IP address
- Unauthorized execution of
useraddcommand - Suspicious use of
sudofor privilege escalation - Multiple authentication failures targeting privileged accounts
These indicators were used to support detection logic and incident analysis.
This project demonstrates practical SOC analyst skills including detection engineering, log analysis, and incident investigation. It reflects real-world security monitoring scenarios and prepares for entry-level SOC Analyst roles.
GitHub: https://github.com/Oykunle/soc-lab-elastic-siem
Oyekunle Alabi
Cybersecurity Student — Ball State University
Focused on building practical blue team and SOC analyst skills through hands-on lab environments.