A Windows to Splunk monitoring system designed for real-time threat detection and security analysis.
This hands-on SOC lab project demonstrates practical cybersecurity skills including SIEM configuration, log analysis, threat detection, and incident response. Built to simulate real-world security operations center workflows and enhance threat hunting capabilities.
Core security monitoring features
Continuous monitoring and analysis of Windows event logs using Splunk for threat detection.
Security events mapped to MITRE ATT&CK framework for standardized threat classification.
Automated alerting and incident response workflows for rapid threat mitigation.
Custom detection rules and dashboards to identify potential security incidents.
Technologies and frameworks used
SIEM platform
Containerization
Log source
Threat framework
Key takeaways from this project