Skip to content

Samin325/Home-Lab-Blue

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

38 Commits
 
 
 
 

Repository files navigation

Homelab for Security Detection & Monitoring

This homelab was created following Day CyberWox’s blueprint and documentation, available on his website. It’s been changed slightly to use more recent software versions and technologies.

The lab was created using VMware Workstation Pro 17. VMware offers a 30-day free trial, which is what I used.

In this lab:

  • pfSense is configured to act as the firewall, router, and DHCP server
  • Splunk is being used as a primary SIEM, and Security Onion has been configured to act as an IDS and secondary SIEM
  • The victim network is comprised of a Windows Server domain controller with a Windows 10 machine in its Active Directory
  • A Kali machine is being used as the attack box.

Network topology: image

Samples:

Connectivity between the Windows 10 user (Eileen) and the Domain Controller:

image

Windows 10 computer in the Active Directory Administrative Center:

image

Login activity logs on Splunk:

image

Nmap scan from the Kali attack box:

image

pfSense dashboard and sample firewall rule:

image

image

Some Security Onion pages/tools:

image

image

image

image

About

Detection and Monitoring Homelab

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published