Skip to content

About

SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

37 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SOC Lab — Elastic SIEM Detection & Incident Response

Technologies: Elastic Stack, Kibana, KQL, Linux, SIEM

This project simulates a Security Operations Center (SOC) environment using the Elastic Stack to detect, analyze, and respond to real-world attack scenarios on a Linux system.

The lab focuses on developing practical blue team skills including threat detection, log analysis, and incident response using SIEM tools.


SOC Investigation Workflow

Each incident follows a structured SOC investigation process:

  1. Alert identification in Kibana (SIEM)
  2. Log analysis using KQL queries
  3. Correlation of timestamps, usernames, and source IP addresses
  4. Identification of suspicious or malicious behavior
  5. Documentation of findings and recommended response actions

Lab Environment

Tools used in this lab:

  • Elastic Stack (Elasticsearch, Kibana)
  • Elastic Agent
  • Ubuntu Linux endpoint
  • Filebeat system authentication logs
  • KQL (Kibana Query Language)

Logs monitored:

  • /var/log/auth.log
  • /var/log/syslog

SOC Skills Demonstrated

This lab demonstrates:

  • SIEM log analysis
  • Linux log analysis
  • Authentication monitoring
  • Threat detection and basic threat hunting
  • Privilege escalation detection
  • Brute force attack detection
  • Detection rule creation using KQL
  • Incident documentation
  • Security investigation workflows

Incident Investigations

Incident Description
Incident 01 Brute force authentication attempts detected against local user account
Incident 02 Privilege escalation activity using sudo detected
Incident 03 Repeated su authentication failures indicating brute-force behavior
Incident 04 Unauthorized user account creation detected using useradd command
Incident 05 SSH authentication failures detected indicating possible brute force attack

All investigations include:

  • Evidence screenshots
  • SIEM queries
  • Security analysis
  • Recommended response actions

Location: /incidents/


MITRE ATT&CK Mapping

The simulated incidents in this lab align with known adversary techniques documented in the MITRE ATT&CK framework.

Incident MITRE Technique Description
Incident 01 T1110 – Brute Force Multiple authentication failures detected against a user account
Incident 02 T1548 – Abuse Elevation Control Mechanism Privilege escalation using sudo
Incident 03 T1110 – Brute Force Repeated su authentication failures indicating brute force attempts
Incident 04 T1136 – Create Account Unauthorized user account creation detected through execution of the useradd command
Incident 05 T1110 – Brute Force Multiple SSH authentication failures detected for user hacker

Reference framework: MITRE ATT&CK

Incident Severity Classification

Each simulated incident is categorized based on potential impact to system security.

Incident Severity Reason
Incident 01 Medium Multiple authentication failures indicating possible brute force
Incident 02 High Privilege escalation using sudo grants root access
Incident 03 Medium Repeated su authentication failures suggest credential guessing
Incident 04 High Unauthorized user account creation indicates persistence attempt
Incident 05 Medium Multiple SSH authentication failures detected for user hacker indicating potential brute force activity

Detection Engineering (KQL Rules)

Detection rules written using Kibana Query Language (KQL) to identify suspicious activity within the Elastic SIEM environment.

Detection KQL Query Description
Brute Force Detection event.dataset : "system.auth" AND message : ("FAILED SU" OR "authentication failure") Detects multiple failed authentication attempts in Linux logs
Privilege Escalation Detection event.dataset : "system.auth" AND message : "sudo" Detects sudo usage and potential privilege escalation
Unauthorized User Creation Detection process.name : "useradd" Detects creation of new user accounts
SSH Brute Force Detection event.dataset : "system.auth" AND message : "authentication failure" Detects SSH authentication failures

Location: /detections/


Evidence Screenshots

Security investigations include supporting evidence from Elastic SIEM dashboards.

Location: /screenshots/

Examples include:

  • Authentication timelines
  • Failed login events
  • Root session activity
  • Privilege escalation logs

Future Improvements

Planned enhancements for this SOC lab include:

  • Detection for suspicious login times (off-hours access)
  • Detection for password spraying attacks across multiple accounts
  • Persistence detection techniques
  • Network reconnaissance detection (Nmap scanning)
  • Alert rule automation and tuning within Elastic SIEM
  • Expanded MITRE ATT&CK mapping across detections

Indicators of Compromise (IOCs)

The following indicators were identified during investigations:

  • Repeated failed authentication attempts from a single IP address
  • Unauthorized execution of useradd command
  • Suspicious use of sudo for privilege escalation
  • Multiple authentication failures targeting privileged accounts

These indicators were used to support detection logic and incident analysis.


Why This Project Matters

This project demonstrates practical SOC analyst skills including detection engineering, log analysis, and incident investigation. It reflects real-world security monitoring scenarios and prepares for entry-level SOC Analyst roles.


Author

GitHub: https://github.com/Oykunle/soc-lab-elastic-siem

Oyekunle Alabi
Cybersecurity Student — Ball State University

Focused on building practical blue team and SOC analyst skills through hands-on lab environments.

About

SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors