Engineered around a segmented multi-tier enterprise architecture featuring an edge OPNsense firewall, a dedicated DMZ with a vulnerable OWASP shop web application for initial entry, isolated Clients & Servers LANs, and full telemetry ingested directly into a centralized SIEM Stack.
This infrastructure isolates external traffic, DMZ exposure, internal workstations, and core server infrastructure. Telemetry across all hosts and firewall boundaries is continuously streamed into the SIEM Stack.
The core network perimeter. Manages routing, traffic filtering, and stateful inspection across WAN (Internet), DMZ, Clients LAN, and Servers LAN while streaming firewall syslogs to the SIEM.
External attacker node positioned across the WAN. Executes initial recon, web application exploits against the DMZ target, payload delivery, and subsequent internal pivot execution.
Positioned in the DMZ as the primary foothold target. Hosts an intentionally vulnerable OWASP shop application exposed to the WAN for web exploit simulations (e.g., SQLi, RCE, Broken Auth). Configured with auditd and forwarders to send full web and system logs to the SIEM.
Internal corporate client endpoint domain-joined to Active Directory. Target for post-exploitation pivots from the compromised DMZ, privilege escalation, and lateral movement. Monitored with Sysmon and Splunk Universal Forwarder.
Core identity provider handling Active Directory domain services, Kerberos authentication, and group policy objects. Central target for credential harvesting, DCSync, and lateral attack paths.
Centralized SOC ingestion and detection engine. Aggregates telemetry across OPNsense, the DMZ OWASP web server, Windows 11 endpoint, and Domain Controller for unified correlation.
Detailed technical documentation of attack chains, detection engineering (SPL queries), and incident response playbooks simulated within the lab.
Exploiting vulnerable web endpoints on the DMZ Linux server to gain initial shell access and correlating web server access logs with SIEM alerts.
Pivoting from the compromised DMZ web server into the internal network, targeting the Windows 11 workstation and detecting SMB/RDP movement.
Harvesting Active Directory credentials, compromising the Domain Controller, and building Splunk correlation rules for Kerberos anomalies.
Deployment of OPNsense firewall with multi-tier routing across WAN, DMZ, Clients LAN, and Servers LAN.
Deployment of the DMZ OWASP Shop web application, Windows 11 endpoint, Domain Controller, and Splunk SIEM Stack with universal forwarder log ingestion.
Simulating an external attack chain: Kali attacking the DMZ OWASP web application, pivoting into Clients LAN, and executing lateral movement toward the Domain Controller.
Crafting custom Splunk SPL correlation searches, mapping attack phases to MITRE ATT&CK techniques, and tuning detection dashboards.