soc-lab
Here are 34 public repositories matching this topic...
Security Playbooks is a collection of MITRE ATT&CK-based attack scenarios, detection rules (Sigma, YARA, Suricata), PoC scripts, and hands-on lab walkthroughs for cybersecurity professionals and SOC analysts.
-
Updated
Jun 1, 2026 - YARA
A set of Windows tools designed for SOC labs and controlled test environments providing automated TLS key logging setup for web encrypted traffic analysis and enabling or disabling of 16 Windows Defender components (9 functional protection components and 7 services/drivers) to support malware research, detection engineering, and Blue Team training.
-
Updated
Jan 11, 2026
🔐 Hands-on SOC lab - 12 tools (OpenSearch, Suricata, Zeek, MISP, Caldera, Velociraptor + AI agents) via Docker Compose. MITRE ATT&CK v14. Free
-
Updated
May 18, 2026 - HTML
Professional High-Concurrency Port Scanner & Vulnerability Auditor | Engineered for SOC & Wazuh SIEM Integration.
-
Updated
Apr 14, 2026 - Python
SOC monitoring lab built using Graylog, OpenSearch, and Ubuntu. Includes log ingestion, detection engineering, alerting, and dashboards.
-
Updated
Mar 5, 2026
ICMP Protocol Analysis Lab using Wireshark – A hands-on cybersecurity lab focused on capturing and analyzing ICMP Echo Request and Reply packets, interpreting protocol fields, and applying Wireshark filters for investigation.
-
Updated
Apr 16, 2025
Building a hands-on Home AD Lab and experimenting with SOC monitoring.
-
Updated
Apr 27, 2026
Your full Guideline on how to install, deploy and use the Wazuh SIEM tool for newbies.
-
Updated
Feb 23, 2026
Attack simulations with full SIEM analysis, Wireshark packet captures, and structured investigation reports - Nmap recon, RDP brute force, and more.
-
Updated
May 27, 2026
A lightweight Home SOC Lab optimized for low-resource devices. Featuring Suricata IDS/IPS, Filebeat on Parrot OS (VM), and Elastic Stack on Docker/WSL2.
-
Updated
May 2, 2026 - PowerShell
End-to-end attack detection lab using Wazuh SIEM, Sysmon, and Windows event log analysis with MITRE ATT&CK mapping.
-
Updated
Mar 5, 2026
Active Directory + Splunk home lab for monitoring Windows authentication events, investigating failed logons, and validating SIEM visibility.
-
Updated
Apr 21, 2026
Mini enterprise SOC lab using Wazuh SIEM/XDR with Windows and Linux endpoints, MITRE ATT&CK mapping, vulnerability detection, and incident reports.
-
Updated
May 8, 2026
-
Updated
Feb 27, 2026
SIEM-based SOC lab with real investigations, telemetry, and detection use cases across Windows & Linux
-
Updated
Mar 15, 2026
A hands-on Azure Cybersecurity lab focused on monitoring real-time RDP brute-force attacks using Windows Event Viewer and Geolocation tracking.
-
Updated
Feb 10, 2026
Improve this page
Add a description, image, and links to the soc-lab topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the soc-lab topic, visit your repo's landing page and select "manage topics."