Authorized Security Lab

Blue Team Lab

Build an authorized detection lab to practice endpoint telemetry, SIEM monitoring and incident investigation.

This lab documents activity performed in an authorized environment.

Environment

Windows endpoint with Sysmon and Wazuh agent, Ubuntu/Wazuh manager, Kali Linux attacker in an isolated lab network.

Architecture

Endpoint telemetry -> Wazuh agent -> Wazuh manager/dashboard; Kali generates controlled test activity.

Tools

Wazuh, Sysmon, Windows, Ubuntu, Kali Linux, Nmap

Configuration

Configure agents, Sysmon rules, logging and dashboards for controlled tests.

Attack Simulation

Run authorized reconnaissance and benign attack simulations only inside the isolated lab.

Detection Method

Correlate Sysmon, Windows and network/security logs in SIEM and review alert rules.

Investigation

Validate source events, timeline activity, process tree, network indicators and affected asset context.

Findings

Document detection gaps, false positives and tuning opportunities.

Lessons Learned

Good lab design separates safe simulation, logging, alerting and evidence review.