Splunk SOC Detection Lab

Project · detection engineering · home lab

Attack scenarios turned into SPL detections over Windows, Sysmon and firewall logs, with a triage runbook for each.

From scenario to detection

Each scenario became an SPL search, then a correlation rule with a tuned threshold. Coverage was mapped to ATT&CK techniques and checked against simulated attacks.

Repeatable triage

Every detection has a runbook: first checks, evidence to collect, and when to escalate.