A defensive Splunk lab built to ingest Windows telemetry, normalize Sysmon events, and validate practical SPL detection use cases.
-
Updated
Aug 7, 2026 - Python
A defensive Splunk lab built to ingest Windows telemetry, normalize Sysmon events, and validate practical SPL detection use cases.
Detect and alert brute-force RDP attacks using Splunk, Windows logs, and a simulated Kali Linux attacker. Home lab project.
A Windows + Splunk SOC detection lab demonstrating log engineering, detection engineering, alert triage, and incident reporting.
TryHackMe walkthrough focused on Windows event logging, Sysmon, and PowerShell-based investigation.
To associate your repository with the windows-logging topic, visit your repo's landing page and select "manage topics."