CW-SIEM-WAZUH-01
Central SIEM platform used for log visibility, alerting, and analyst investigations.
Lab Architecture
Built to simulate how a Tier 1 analyst monitors endpoints, validates alerts, and investigates suspicious activity across Windows and Linux systems.
Machine Roles
Central SIEM platform used for log visibility, alerting, and analyst investigations.
Primary Windows endpoint representing a business workstation and key source of security telemetry.
Internal Linux server used to extend monitoring beyond Windows and practice cross-platform analysis.
Adversary simulation system used to generate realistic attack traffic and evidence for investigation.
Build Process
SOC Data Flow
Skills Demonstrated