Project overview
This lab is designed to connect attacker activity with defensive visibility. Controlled actions are performed against isolated systems, telemetry is collected and detections are developed or refined based on the observed evidence.
Planned workflow
- Define the behavior to test and the permitted lab scope.
- Generate endpoint, authentication and network telemetry.
- Investigate the activity in a SIEM or analysis tool.
- Write or refine detection content.
- Re-run the test and compare the evidence.
- Document assumptions, blind spots and false-positive conditions.
Technologies
The environment may use Windows endpoints, Kali Linux, Sysmon, Splunk, Wazuh, Zeek, Sigma rules and supporting forensic utilities depending on the exercise.
Safety boundary
All testing is restricted to systems owned or explicitly authorized for the lab.