My Portfolio

Join me in my cybersecurity journey to become a world-class security engineer

View on GitHub

ELK SOC Lab Setup and Configuration – 01/10/2024

In this lab, I set up an ELK stack (Elasticsearch, Logstash, Kibana) SOC on Vultr to simulate the implementation and configuration of a Security Information and Event Management (SIEM) system within a Virtual Private Cloud (VPC). The project included configuring various systems, simulating a brute force attack using Mythic C2, and creating custom dashboards for alerting and monitoring security events. Below is a detailed step-by-step breakdown of the lab configuration.

This is the Lab logical diagram: Labdiagram

1. VPC and Elasticsearch Server Configuration:

VPC Setup:

Elasticsearch Installation:

Kibana Installation:

2. Windows Client Configuration:

3. Fleet Server Configuration:

Fleet Server Setup:

Agent Deployment:

4. Data Ingestion and Custom Integrations:

Windows Data Ingestion:

Ubuntu Server Configuration:

5. Custom Dashboards:

Dashboard 1:

Dashboard 2:

6. Mythic C2 Server and Agent Setup:

Mythic Server Deployment:

This is the Attack diagram:

Labdiagram

Mythic Agent Configuration:

7. Brute Force Attack Simulation:

Kali Linux Setup:

8. osTicket Setup and Integration:

osTicket Installation:

osTicket and ELK Integration: