● STATUS: ONLINE _

Production-Style SOC Detection Lab.

Engineered around a segmented multi-tier enterprise architecture featuring an edge OPNsense firewall, a dedicated DMZ with a vulnerable OWASP shop web application for initial entry, isolated Clients & Servers LANs, and full telemetry ingested directly into a centralized SIEM Stack.

// NETWORK ZONES
3 Subnets
// ENTRY POINT
OWASP App
// SIEM CORE
Splunk Ent.
// ARCHITECTURE
v3.0

>Lab_Infrastructure.yaml

This infrastructure isolates external traffic, DMZ exposure, internal workstations, and core server infrastructure. Telemetry across all hosts and firewall boundaries is continuously streamed into the SIEM Stack.

ACTIVE

OPNsense Firewall

The core network perimeter. Manages routing, traffic filtering, and stateful inspection across WAN (Internet), DMZ, Clients LAN, and Servers LAN while streaming firewall syslogs to the SIEM.

Perimeter Routing Syslog
ACTIVE

Kali Machine

External attacker node positioned across the WAN. Executes initial recon, web application exploits against the DMZ target, payload delivery, and subsequent internal pivot execution.

Offensive External WAN

:: DMZ.zone ATTACK ENTRY PERIMETER

ENTRY POINT

Linux Web Server (Vulnerable OWASP Shop)

Positioned in the DMZ as the primary foothold target. Hosts an intentionally vulnerable OWASP shop application exposed to the WAN for web exploit simulations (e.g., SQLi, RCE, Broken Auth). Configured with auditd and forwarders to send full web and system logs to the SIEM.

OWASP Shop Initial Access DMZ Host Splunk UF

:: CLIENTS_LAN.zone

ACTIVE

Windows 11 Workstation

Internal corporate client endpoint domain-joined to Active Directory. Target for post-exploitation pivots from the compromised DMZ, privilege escalation, and lateral movement. Monitored with Sysmon and Splunk Universal Forwarder.

Windows 11 Sysmon Endpoint Telemetry

:: SERVERS_LAN.zone

ACTIVE

Domain Controller (AD DS)

Core identity provider handling Active Directory domain services, Kerberos authentication, and group policy objects. Central target for credential harvesting, DCSync, and lateral attack paths.

Active Directory Security Logs
ACTIVE

SIEM Stack (Splunk Enterprise)

Centralized SOC ingestion and detection engine. Aggregates telemetry across OPNsense, the DMZ OWASP web server, Windows 11 endpoint, and Domain Controller for unified correlation.

Splunk Enterprise Detection SIEM

>_Visuals.img

Lab Architecture Overview
01_soc_network_architecture_diagram.png
Vulnerable OWASP Juice Shop Application
02_vulnerable_owaspshop.png
OPNsense Firewall Dashboard
03_opnsense_dashboard.png
OPNsense Firewall Rules Matrix
04_opnsense_rules_matrix.png
OPNsense Interface & Console State
05_opnsense_console_screen.png

>ls -la ./writeups

Detailed technical documentation of attack chains, detection engineering (SPL queries), and incident response playbooks simulated within the lab.

WIP

Initial Foothold: OWASP Shop

Exploiting vulnerable web endpoints on the DMZ Linux server to gain initial shell access and correlating web server access logs with SIEM alerts.

T1190
WIP

DMZ to Clients LAN Pivot

Pivoting from the compromised DMZ web server into the internal network, targeting the Windows 11 workstation and detecting SMB/RDP movement.

T1021.002
WIP

Domain Compromise & Detection

Harvesting Active Directory credentials, compromising the Domain Controller, and building Splunk correlation rules for Kerberos anomalies.

T1558.001

tail -froadmap.log

[ ✔ ] PHASE 1 : COMPLETE

Network Segmentation & Firewall Setup

Deployment of OPNsense firewall with multi-tier routing across WAN, DMZ, Clients LAN, and Servers LAN.

[ ✔ ] PHASE 2 : COMPLETE

Host Provisioning & Telemetry Pipeline

Deployment of the DMZ OWASP Shop web application, Windows 11 endpoint, Domain Controller, and Splunk SIEM Stack with universal forwarder log ingestion.

[ ⟳ ] PHASE 3 : IN PROGRESS

End-to-End Attack Emulation

Simulating an external attack chain: Kali attacking the DMZ OWASP web application, pivoting into Clients LAN, and executing lateral movement toward the Domain Controller.

[ ◻ ] PHASE 4 : UPCOMING

Detection Engineering & Alert Correlation

Crafting custom Splunk SPL correlation searches, mapping attack phases to MITRE ATT&CK techniques, and tuning detection dashboards.