Home SOC Lab Pack · Lab 9, built first as the foundation for Labs 1-8
Every one of the nine labs in this pack assumes a working detection and response platform already exists underneath it. A brute force detection lab needs somewhere to send failed logon events. A phishing investigation lab needs mail and endpoint telemetry already flowing somewhere. Rather than build each lab on an ad hoc setup, this one, a fully self-hosted monitoring environment across four endpoints, two Windows and two Linux, split across two physical host machines, came first. It isn't one project among nine, it's the platform the other eight run on top of.
Every sensor, Sysmon, Suricata, Zeek, the Wazuh agents, was installed and then independently verified with real evidence: an actual alert generated, correctly classified, and traced end to end into the dashboard, not just a service showing "active."
Four endpoints across two physical hosts, bridged networking rather than NAT or host-only so the topology could actually span both machines, with Tailscale layered on top for secure remote access to the lab and its dashboard without exposing any host directly to the internet.
Before any security tooling went in, the base environment itself had to be built: Windows Server and Windows 11 ISOs downloaded and verified, then four virtual machines provisioned and onboarded across two physical hosts, HOM-PC-W001 (Windows 11, 2 vCPU, 4GB RAM, 64GB storage), HOM-SVR-W004 (Windows Server 2022, 2 vCPU, 4GB RAM, 60GB storage), HOM-PC-L002 (Ubuntu 22.04.5 LTS, 2 vCPU, 4GB RAM, 40GB storage), and HOM-PC-L003 (Ubuntu 22.04.5 LTS, 2 vCPU, 4GB RAM, 60GB storage, designated as the Wazuh Manager host). Routine installer and provisioning screenshots aren't included here since they don't add evidentiary value beyond this summary, the sections below pick up from the first piece of actual security tooling.
Wazuh 4.14 was installed as a single-node, all-in-one deployment, manager, indexer, and dashboard, on HOM-PC-L003, with firewall access configured for agent events (1514/tcp), agent enrollment (1515/tcp), the Manager API (55000/tcp), and dashboard access (443/tcp).
Suricata 8.0.7 was deployed on every endpoint. On the Linux hosts it loaded 52,902 Emerging Threats Open signatures without failures; on the Windows hosts, Npcap handled packet capture after resolving an initial access violation caused by referencing the network adapter by friendly name instead of its Npcap device identifier.
Action1 was deployed as an independent SaaS RMM layer across all four endpoints, added for software inventory and patch-management visibility, kept deliberately separate from Wazuh rather than feeding into it directly.
Tailscale was installed on all four hosts to provide encrypted remote access to the lab and its dashboard without exposing any host directly to the internet.
Sysmon was deployed on both Windows hosts using the SwiftOnSecurity configuration template, then verified directly in Event Viewer before confirming it was reaching Wazuh.
With every sensor in place, Wazuh Agent enrollment was confirmed across the three monitored endpoints reporting into the manager on HOM-PC-L003.
Zeek was added to the two Linux hosts for protocol-level visibility and scan detection alongside Suricata's signature matching. The first scan-detection test didn't go cleanly, which is worth showing rather than hiding.
With the full stack verified, independently, with real evidence rather than a service status check, this environment became the foundation the other eight labs in the pack build on. Two stack-wide config fixes came out of this process too: disabling Suricata's eve-log stats block (it was flooding Wazuh's JSON decoder) and enabling full archive logging so every event, not only alerts, reaches the indexer.
The full project report, including every installation step and additional screenshots, is documented on Notion.