Home Lab

I’m building a SOC‑focused homelab designed to simulate adversary behavior, collect endpoint telemetry, and develop practical detection engineering skills. This page outlines the roadmap, environment goals, and ongoing work as the project evolves.


Roadmap

Phase 1 — Repo + Environment Setup

Windows VM created, PowerShell logging enabled, Sysmon installed with SwiftOnSecurity config.
Next Steps: Azure onboarding and Azure Monitor Agent deployment

Phase 2 — Threat Simulation

Validate ingestion, install Atomic Red Team, run initial tests.

Phase 3 — Detection Engineering

KQL rules, analytics, hunting queries, detection testing.

Phase 4 — Documentation

Methodology, incident reports, architecture diagram.

Phase 5 — Final Polish

README updates, screenshots, release v1.0.


Overview

This homelab models a small SOC environment using Windows endpoint telemetry, Sysmon, Azure Monitor Agent, and Microsoft Sentinel. It supports threat simulation, log ingestion validation, KQL‑based detection engineering, and incident response documentation.


Plans

Below are the active tasks and components being built into the lab.

Azure Arc onboarding AMA deployment Sysmon ingestion validation Atomic Red Team Attack simulations Event ID analysis KQL rule development Detection testing Documentation Incident reports Architecture diagram Repo publish

Coming Soon

New content is on its way. Diagrams, detections, and investigations will appear here as the lab evolves.