I’m building a SOC‑focused homelab designed to simulate adversary behavior, collect endpoint telemetry, and develop practical detection engineering skills. This page outlines the roadmap, environment goals, and ongoing work as the project evolves.
Windows VM created, PowerShell logging enabled, Sysmon installed with SwiftOnSecurity config.
Next Steps: Azure onboarding and Azure Monitor Agent deployment
Validate ingestion, install Atomic Red Team, run initial tests.
KQL rules, analytics, hunting queries, detection testing.
Methodology, incident reports, architecture diagram.
README updates, screenshots, release v1.0.
This homelab models a small SOC environment using Windows endpoint telemetry, Sysmon, Azure Monitor Agent, and Microsoft Sentinel. It supports threat simulation, log ingestion validation, KQL‑based detection engineering, and incident response documentation.
Below are the active tasks and components being built into the lab.
New content is on its way. Diagrams, detections, and investigations will appear here as the lab evolves.