A compact, hands-on SOC lab showcasing centralized logging, IDS/IPS detection, WAF-like filtering, and incident handling across a multi-OS environment.

Core Stack:
Platforms & Infra:
Attack & Test Tooling:
Wazuh (SIEM)Suricata IDS/IPS (incl. anti-XSS rules)Nginxconfigs/nginx.confconfigs/xss.rulesconfigs/ubuntu/ossec.confconfigs/windows/ossec.confconfigs/ubuntu/hostsconfigs/windows/hostsThis tested emphasizes the importance of centralized telemetry and layered defenses. It provides a reproducible foundation for expanding into SOAR, CTI integration, and hybrid cloud deployments while validating detection logic with realistic attack simulations.