
If you want a fully functional Security Operations Center (SOC) home lab but don’t know where to start or you want someone to sit with you and deploy it end-to-end - I’ll work with you live and build it together. Even if you only have a low-end laptop, I’ll walk you through using affordable cloud VMs (DigitalOcean / Google Cloud) or local VMs and deploy a repeatable, working SOC environment.
WHAT TO EXPECT?
🔹4 live sessions (weekends or weekdays, as arranged & based on our mutual availabilities)
🔹Initial discovery + planning call, then 4 implementation/deploy calls.
🔹Each session: minimum 1.5–2 hours of live, interactive work.4. We will deploy the lab on the fly while you follow along (or I can do most of the deployment while you observe).
✦ Initial setup call to understand your environment, goals, budget, and which use-cases you care about.
✦ Cloud or local deployment guidance (I’ll help you set up DigitalOcean / Google Cloud accounts if needed, or optimize for a low-end local machine).
✦ Full SOC stack deployment (open-source / free tools only unless you request otherwise).
✦ Use-case development & detection rules: write and test detection logic for common attacks.
✦ Alerting, SOAR automation & enrichment: build automation runbooks, TI enrichment, and alert workflows.
✦ Case management: configure case handling and triage workflows (TheHive, DFIR IRIS, or ELK case workflows).
✦ Post-session deliverables: architecture diagram, config snippets, detection queries (Elastic/SPL/KQL variants where applicable), SOAR playbooks, and a short runbook for reproducing the environment.
✦ Follow-up support: short post-delivery Q&A window (I’ll answer clarifying questions and help troubleshoot basic issues after final session).
Tools we can deploy and integrate
We’ll stick to free / open-source tools unless you ask otherwise.
Typical toolset options:
• SIEM / logs: Elastic Stack (ELK), Wazuh, Splunk (free tier / trial guidance)
• SOAR / automation: n8n, Shuffle, TraceCat
• Case management: TheHive, DFIR IRIS, ELK case management options
• Threat intel / enrichment: MISP, AlienVault OTX, VirusTotal (API), custom TI enrichers
• Network / IDS: Suricata, Zeek (sample logs or live capture)
• Endpoint logs / telemetry: Windows + Sysmon, Linux auditd
• Red team / simulation: Caldera, Atomic Red Team
• Auxiliary: Elastic Agent / Beats, Filebeat, Winlogbeat, Sigma conversions, sample log generators
Log sources & sample data
• Windows + Sysmon telemetry (process, network, registry, file, PowerShell)
• Linux audit logs, syslog
• Firewall logs (sample files / ingestion)
• Suricata IDS alerts
• DNS logs (sample logs for tunneling and data exfiltration test cases)
• Simulated phish / email logs (sample SMTP/Exchange) and attachment handling
Some references to technical use-cases that I can cover (more included).
(Each use-case will include: log ingestion → detection rule → alert → SOAR playbook → case creation)
• Brute-force / Credential stuffing (T1110) — failed logon spikes, account lockouts, IP correlation
• Privilege escalation detection (T1068 / T1548) — suspicious token or service creation, unusual module loading
• Golden Ticket / Kerberos abuse (T1558.001) — anomalous TGT lifetimes, unusual SID/privileges
• Lateral movement (Pass-the-Hash / WMI / Remote Services) (T1021 / T1047) — remote execution patterns, remote scheduled tasks
• Credential dumping (LSASS / Mimikatz patterns) (T1003) — process memory access, suspicious DLL injection
Deliverables you will receive
Who this is for?
• Security students who want practical hands-on experience.
• Engineers who want to prototype a SOC stack before buying commercial tools.
• SOC analysts who want a lab to test detections, playbooks, and practice incident response.
• Hobbyists or professionals looking for a repeatable, documented SOC sandbox.
NOTE: This is a deployment assistance, not a course or training. I’ll help you build and deliver a working SOC home lab. This is not a formal training.