This Home SOC lab establishes a fully functional, self-hosted security monitoring environment across four endpoints, two Windows and two Linux, split across two physical host machines. It integrates a central SIEM (Wazuh), host-level endpoint telemetry (Sysmon), network intrusion detection (Suricata), protocol-level network analysis (Zeek), patch and remote management (Action1), and secure remote access (Tailscale) into a single working platform.
Every component was not only installed but individually verified with real, evidenced detections, correctly classified alerts, MITRE ATT&CK-mapped events, and confirmed log ingestion end to end into the Wazuh dashboard. Several genuine technical issues were identified and resolved during this process, including a deprecated Zeek detection script, a platform-specific Suricata capture defect on Windows, and a data volume limitation in Wazuh's log parser, each representative of real-world deployment challenges a SOC analyst would be expected to diagnose and resolve independently.
With this foundation confirmed operational, the environment is ready to support the detection and investigation labs that follow, each of which depends on the telemetry, correlation, and alerting capability established here.
Every one of the nine labs in this pack assumes a working detection and response platform already exists underneath it. A brute force detection lab needs somewhere to send failed logon events. A phishing investigation lab needs a case management system to open. A network threat hunt needs sensors already watching the wire. None of that can be simulated convincingly on its own, it has to actually be there, actually working, before the lab that depends on it can begin.
That's the reasoning behind building Lab 9 first rather than last. It isn't simply one project among nine, it's the platform the other eight run on top of. A SOC analyst doesn't get handed detections in isolation either, they inherit an already-deployed stack of agents, sensors, and a SIEM, and their job is to use it, tune it, and investigate through it. Building that stack from nothing first, and proving every piece of it actually works, mirrors that reality far more closely than treating each lab as a disconnected exercise with its own throwaway setup.
That proof mattered more than the build itself. Each sensor, Sysmon, Suricata, Zeek, the Wazuh agents, was installed, then independently verified with real evidence: an actual alert generated, correctly classified, and traced end to end into the dashboard, not just a service showing "running." Several genuine issues surfaced during that process, a removed core Zeek script, a Suricata bug specific to Windows interface binding, a Wazuh decoder limitation, a logcollector timing gap on restart, none of which would have been visible without deliberately testing every path rather than trusting a clean install. Finding and resolving those issues here, once, means Labs 1 through 8 can each focus on the actual detection logic and investigation workflow they're meant to teach, not on rediscovering the same plumbing problems eight separate times.
That's what makes this the backbone: every detection Lab 1 fires, every case Lab 2 opens, every packet Lab 4 hunts through, depends on telemetry that only reaches an analyst's screen because this foundation was built, broken, fixed, and confirmed first.
Research findings, data insights, and key considerations
Proposed solutions, strategies, and next steps
Chosen as the SIEM core because it is open source, widely used in real SOC environments, and combines log collection, correlation, and visualization in a single platform, no separate ELK stack required. Manager, indexer, and dashboard run on HOM-PC-L003. Agents deployed on the three remaining endpoints; L003 self-monitors via its built-in local agent (ID 000). Full archive logging (logall, logall_json) enabled so all events are indexed, not only those matching an existing rule, supporting later Sigma-style rule development.
Deployed on the two Windows endpoints (HOM-PC-W001, HOM-PC-W004) to capture host-level telemetry standard Windows auditing misses: full process creation with command line, parent-child lineage, file creation, and registry activity. Wired into Wazuh via the Microsoft-Windows-Sysmon/Operational event channel using eventchannel log format. This is the primary data source for the Windows brute force and PowerShell attack labs.
Chosen as the IDS layer for signature-based network detection using the Emerging Threats Open ruleset. Deployed on all four endpoints in AF_PACKET (Linux) or Npcap (Windows) capture mode, so each host also inspects its own local traffic, not only what a central sensor can see. eve.json alerts wired into Wazuh on all four. The default stats event type was disabled on every host after it was found to exceed Wazuh's JSON decoder field limit.