← Calyvex Lab
ProjectActive development

Security Detection & Attack Simulation Lab

A controlled Windows and Linux environment for generating telemetry, testing detections and documenting analyst investigations.

SplunkWazuhSysmonWindowsKali LinuxSigma

Project overview

This lab is designed to connect attacker activity with defensive visibility. Controlled actions are performed against isolated systems, telemetry is collected and detections are developed or refined based on the observed evidence.

Planned workflow

  1. Define the behavior to test and the permitted lab scope.
  2. Generate endpoint, authentication and network telemetry.
  3. Investigate the activity in a SIEM or analysis tool.
  4. Write or refine detection content.
  5. Re-run the test and compare the evidence.
  6. Document assumptions, blind spots and false-positive conditions.

Technologies

The environment may use Windows endpoints, Kali Linux, Sysmon, Splunk, Wazuh, Zeek, Sigma rules and supporting forensic utilities depending on the exercise.

Safety boundary

All testing is restricted to systems owned or explicitly authorized for the lab.

Build with Calyvex

Need a practical security solution?

Tell us what you are trying to detect, understand, validate or improve.