Four-Endpoint Home SOC Setup

Home SOC Lab Pack · Lab 9, built first as the foundation for Labs 1-8

Solo build · 4 endpoints across 2 physical hosts · Wazuh, Sysmon, Suricata, Zeek, Action1, Tailscale

Why this lab came first

Every one of the nine labs in this pack assumes a working detection and response platform already exists underneath it. A brute force detection lab needs somewhere to send failed logon events. A phishing investigation lab needs mail and endpoint telemetry already flowing somewhere. Rather than build each lab on an ad hoc setup, this one, a fully self-hosted monitoring environment across four endpoints, two Windows and two Linux, split across two physical host machines, came first. It isn't one project among nine, it's the platform the other eight run on top of.

Every sensor, Sysmon, Suricata, Zeek, the Wazuh agents, was installed and then independently verified with real evidence: an actual alert generated, correctly classified, and traced end to end into the dashboard, not just a service showing "active."

Network architecture

Four endpoints across two physical hosts, bridged networking rather than NAT or host-only so the topology could actually span both machines, with Tailscale layered on top for secure remote access to the lab and its dashboard without exposing any host directly to the internet.

Home SOC security monitoring architecture diagram showing four endpoints, the Wazuh manager, and Action1 cloud
The as-built architecture: four endpoints, each running Wazuh Agent, Suricata, Action1, and Tailscale, with HOM-PC-L003 hosting the Wazuh Manager, Indexer, and Dashboard, plus Zeek on the two Linux hosts.

Environment provisioning

Before any security tooling went in, the base environment itself had to be built: Windows Server and Windows 11 ISOs downloaded and verified, then four virtual machines provisioned and onboarded across two physical hosts, HOM-PC-W001 (Windows 11, 2 vCPU, 4GB RAM, 64GB storage), HOM-SVR-W004 (Windows Server 2022, 2 vCPU, 4GB RAM, 60GB storage), HOM-PC-L002 (Ubuntu 22.04.5 LTS, 2 vCPU, 4GB RAM, 40GB storage), and HOM-PC-L003 (Ubuntu 22.04.5 LTS, 2 vCPU, 4GB RAM, 60GB storage, designated as the Wazuh Manager host). Routine installer and provisioning screenshots aren't included here since they don't add evidentiary value beyond this summary, the sections below pick up from the first piece of actual security tooling.

Technology stack and rationale

Wazuh Manager deployment

Wazuh 4.14 was installed as a single-node, all-in-one deployment, manager, indexer, and dashboard, on HOM-PC-L003, with firewall access configured for agent events (1514/tcp), agent enrollment (1515/tcp), the Manager API (55000/tcp), and dashboard access (443/tcp).

Terminal output showing the Wazuh install and firewall configuration commands
Wazuh install and firewall configuration on HOM-PC-L003.
Wazuh dashboard login page loading successfully after installation
Wazuh fully installed and the dashboard login page loading.
Successful login to the Wazuh dashboard
Successful login to the Wazuh dashboard, confirming the SIEM core is live.

Suricata IDS across all four endpoints

Suricata 8.0.7 was deployed on every endpoint. On the Linux hosts it loaded 52,902 Emerging Threats Open signatures without failures; on the Windows hosts, Npcap handled packet capture after resolving an initial access violation caused by referencing the network adapter by friendly name instead of its Npcap device identifier.

Suricata on HOM-PC-L003 confirming 52,902 rules successfully loaded
Suricata on HOM-PC-L003: 52,902 rules loaded successfully, 0 failed, 0 skipped.
Suricata rules downloaded on HOM-PC-L002
Suricata rules downloaded on HOM-PC-L002.
Suricata service confirmed running on HOM-PC-L002 after restart
Suricata service confirmed running on HOM-PC-L002 after restart.
Wazuh ingesting Suricata eve.json alerts on HOM-SVR-W004 with severity and MITRE mapping
Wazuh ingesting Suricata's eve.json alerts via its native decoder on HOM-SVR-W004, classified with severity and MITRE mapping, confirming the Suricata-to-Wazuh integration end to end.
Emerging Threats Open ruleset installed on HOM-PC-W001
Emerging Threats Open ruleset installed on HOM-PC-W001, the last of the four endpoints to come online.
Simulating network traffic on HOM-PC-W001 to prove Suricata is capturing live traffic
Simulating traffic on HOM-PC-W001 to prove Suricata is capturing live, not just configured.
GPL ATTACK_RESPONSE id check returned root alert confirmed on the Wazuh Manager
The "GPL ATTACK_RESPONSE id check returned root" test alert confirmed on the Wazuh Manager (HOM-PC-L003).
The simulated attack alert visible on the Wazuh dashboard
The same simulated attack firing alerts visible on the Wazuh dashboard, captured from both HOM-PC-W001 and HOM-SVR-W004.
Live attack simulation traffic captured by Suricata on HOM-PC-W001
Live attack simulation traffic captured directly by the Suricata sensor on HOM-PC-W001.
All four endpoints confirmed reporting live Suricata traffic
All four endpoints confirmed reporting live traffic, Suricata is fully operational across the lab.

Action1 patch management

Action1 was deployed as an independent SaaS RMM layer across all four endpoints, added for software inventory and patch-management visibility, kept deliberately separate from Wazuh rather than feeding into it directly.

Action1 deployed on HOM-PC-L003
Action1 deployed on HOM-PC-L003, the first endpoint onboarded.
Action1 enrollment complete across all four lab endpoints
Action1 enrollment complete across all four endpoints: HOM-PC-L002, HOM-PC-L003, HOM-SVR-W004, and HOM-PC-W001.

Tailscale secure connectivity

Tailscale was installed on all four hosts to provide encrypted remote access to the lab and its dashboard without exposing any host directly to the internet.

Tailscale installed on HOM-PC-L003
Tailscale installed on HOM-PC-L003, the Wazuh Manager host.
Tailscale enrollment complete across all four lab endpoints
Final enrollment check: all four endpoints connected to the Tailscale network.

Sysmon Windows telemetry

Sysmon was deployed on both Windows hosts using the SwiftOnSecurity configuration template, then verified directly in Event Viewer before confirming it was reaching Wazuh.

Sysmon Process Creation events visible in Windows Event Viewer
Sysmon verified in Event Viewer: Process Creation (Event ID 1) and network events streaming into the Microsoft-Windows-Sysmon/Operational log.
Sysmon installed, configured, and verified running on HOM-SVR-W004
Sysmon installed, configured, and confirmed running on HOM-SVR-W004.
Sysmon alerting from both Windows machines confirmed on the Wazuh Manager
Sysmon alerting from both Windows machines to the Wazuh Manager, confirmed end to end.

Wazuh agent onboarding

With every sensor in place, Wazuh Agent enrollment was confirmed across the three monitored endpoints reporting into the manager on HOM-PC-L003.

Wazuh agents successfully onboarded on the monitored endpoints
Wazuh Agent successfully onboarded across the monitored endpoints.
Wazuh agents showing active status on the manager
All onboarded agents confirmed active on the Wazuh Manager.

Zeek network traffic analysis

Zeek was added to the two Linux hosts for protocol-level visibility and scan detection alongside Suricata's signature matching. The first scan-detection test didn't go cleanly, which is worth showing rather than hiding.

Zeek live traffic capture confirmed through conn.log entries on HOM-PC-L003
Zeek live capture confirmed on HOM-PC-L003 through entries appearing in conn.log.
Zeek deployed and capturing live network traffic on HOM-PC-L002
Zeek deployed and verified capturing live traffic on HOM-PC-L002.
Zeek CaptureLoss notice fired instead of a scan detection on the first simulated nmap scan
The first simulated nmap scan didn't trigger a scan-detection notice, instead surfacing Zeek's own CaptureLoss::Too_Much_Loss notice at over 28% packet loss, a genuine troubleshooting step rather than an immediate clean result.
Wazuh dashboard confirming a genuine Zeek Scan::Port_Scan detection
The confirmed detection: rule.id 100101, data.note Scan::Port_Scan, 192.168.100.97 scanned at least 20 unique ports, visible in the Wazuh dashboard.
Full Zeek scan-detection stack validated on HOM-PC-L003 with JSON logging and increased capture buffer
Full Zeek scan-detection stack validated on HOM-PC-L003, JSON logging and an increased capture buffer applied upfront based on the lessons learned from HOM-PC-L002.

With the full stack verified, independently, with real evidence rather than a service status check, this environment became the foundation the other eight labs in the pack build on. Two stack-wide config fixes came out of this process too: disabling Suricata's eve-log stats block (it was flooding Wazuh's JSON decoder) and enabling full archive logging so every event, not only alerts, reaches the indexer.

The full project report, including every installation step and additional screenshots, is documented on Notion.

View full report on Notion →