Splunk SOC Detection Lab
Project · detection engineering · home lab
Attack scenarios turned into SPL detections over Windows, Sysmon and firewall logs, with a triage runbook for each.
- Context Home lab
- Data Windows Event Logs · Sysmon · firewall
- Detections Brute force · privilege escalation · lateral movement
- Mapping MITRE ATT&CK
From scenario to detection
Each scenario became an SPL search, then a correlation rule with a tuned threshold. Coverage was mapped to ATT&CK techniques and checked against simulated attacks.
Repeatable triage
Every detection has a runbook: first checks, evidence to collect, and when to escalate.