Authorized Security Lab
Blue Team Lab
Build an authorized detection lab to practice endpoint telemetry, SIEM monitoring and incident investigation.
This lab documents activity performed in an authorized environment.
Environment
Windows endpoint with Sysmon and Wazuh agent, Ubuntu/Wazuh manager, Kali Linux attacker in an isolated lab network.
Architecture
Endpoint telemetry -> Wazuh agent -> Wazuh manager/dashboard; Kali generates controlled test activity.
Tools
Wazuh, Sysmon, Windows, Ubuntu, Kali Linux, Nmap
Configuration
Configure agents, Sysmon rules, logging and dashboards for controlled tests.
Attack Simulation
Run authorized reconnaissance and benign attack simulations only inside the isolated lab.
Detection Method
Correlate Sysmon, Windows and network/security logs in SIEM and review alert rules.
Investigation
Validate source events, timeline activity, process tree, network indicators and affected asset context.
Findings
Document detection gaps, false positives and tuning opportunities.
Lessons Learned
Good lab design separates safe simulation, logging, alerting and evidence review.