Lets Build Your Home Lab!

Urvesh Urvesh

profile
Best Seller
Lets Build Your Home Lab!
profile
Digital Product

If you want a fully functional Security Operations Center (SOC) home lab but don’t know where to start or you want someone to sit with you and deploy it end-to-end - I’ll work with you live and build it together. Even if you only have a low-end laptop, I’ll walk you through using affordable cloud VMs (DigitalOcean / Google Cloud) or local VMs and deploy a repeatable, working SOC environment.


WHAT TO EXPECT?

🔹4 live sessions (weekends or weekdays, as arranged & based on our mutual availabilities)

🔹Initial discovery + planning call, then 4 implementation/deploy calls.

🔹Each session: minimum 1.5–2 hours of live, interactive work.4. We will deploy the lab on the fly while you follow along (or I can do most of the deployment while you observe).


✦ Initial setup call to understand your environment, goals, budget, and which use-cases you care about.

Cloud or local deployment guidance (I’ll help you set up DigitalOcean / Google Cloud accounts if needed, or optimize for a low-end local machine).

Full SOC stack deployment (open-source / free tools only unless you request otherwise).

Use-case development & detection rules: write and test detection logic for common attacks.

Alerting, SOAR automation & enrichment: build automation runbooks, TI enrichment, and alert workflows.

Case management: configure case handling and triage workflows (TheHive, DFIR IRIS, or ELK case workflows).

Post-session deliverables: architecture diagram, config snippets, detection queries (Elastic/SPL/KQL variants where applicable), SOAR playbooks, and a short runbook for reproducing the environment.

Follow-up support: short post-delivery Q&A window (I’ll answer clarifying questions and help troubleshoot basic issues after final session).


Tools we can deploy and integrate

We’ll stick to free / open-source tools unless you ask otherwise.


Typical toolset options:

• SIEM / logs: Elastic Stack (ELK), Wazuh, Splunk (free tier / trial guidance)

• SOAR / automation: n8n, Shuffle, TraceCat

• Case management: TheHive, DFIR IRIS, ELK case management options

• Threat intel / enrichment: MISP, AlienVault OTX, VirusTotal (API), custom TI enrichers

• Network / IDS: Suricata, Zeek (sample logs or live capture)

• Endpoint logs / telemetry: Windows + Sysmon, Linux auditd

• Red team / simulation: Caldera, Atomic Red Team

• Auxiliary: Elastic Agent / Beats, Filebeat, Winlogbeat, Sigma conversions, sample log generators


Log sources & sample data

• Windows + Sysmon telemetry (process, network, registry, file, PowerShell)

• Linux audit logs, syslog

• Firewall logs (sample files / ingestion)

• Suricata IDS alerts

• DNS logs (sample logs for tunneling and data exfiltration test cases)

• Simulated phish / email logs (sample SMTP/Exchange) and attachment handling


Some references to technical use-cases that I can cover (more included).

(Each use-case will include: log ingestion → detection rule → alert → SOAR playbook → case creation)

• Brute-force / Credential stuffing (T1110) — failed logon spikes, account lockouts, IP correlation

• Privilege escalation detection (T1068 / T1548) — suspicious token or service creation, unusual module loading

• Golden Ticket / Kerberos abuse (T1558.001) — anomalous TGT lifetimes, unusual SID/privileges

• Lateral movement (Pass-the-Hash / WMI / Remote Services) (T1021 / T1047) — remote execution patterns, remote scheduled tasks

• Credential dumping (LSASS / Mimikatz patterns) (T1003) — process memory access, suspicious DLL injection


Deliverables you will receive

  1. Working, reproducible SOC lab running the chosen stack (cloud or local)
  2. Architecture diagram & deployment steps (so you can rebuild)
  3. Config files and scripts used (beats, agents, collectors, parsers)
  4. Detection rules / queries (Elastic DSL, Splunk SPL, and Sigma where relevant)
  5. SOAR runbooks / automation flows (n8n / Shuffle JSON or playbook files)
  6. Case management configuration and example cases
  7. Threat intel integration scripts / connectors
  8. List of test scenarios, sample logs, and how to run attack simulations safely


Who this is for?

• Security students who want practical hands-on experience.

• Engineers who want to prototype a SOC stack before buying commercial tools.

• SOC analysts who want a lab to test detections, playbooks, and practice incident response.

• Hobbyists or professionals looking for a repeatable, documented SOC sandbox.


NOTE: This is a deployment assistance, not a course or training. I’ll help you build and deliver a working SOC home lab. This is not a formal training.


11,00013,200