A mini Security Operations Center (SOC) environment showcasing real-world threat detection using Splunk Enterprise, Sysmon, and Atomic Red Team with MITRE ATT&CK framework mapping.
Technologies Used
Splunk EnterpriseSysmonAtomic Red TeamVirtualBoxWindows 10Ubuntu Server
Key Highlights
End-to-end attacker simulation and detection
Real-time alerting and correlation logic
MITRE ATT&CK framework alignment
Comprehensive SIEM deployment and detection engineering
Explore technical details
Technical Implementation
Windows 10 VM configured as target endpoint with Splunk Universal Forwarder
Ubuntu Server VM hosting Splunk Enterprise for centralized log analysis
Sysmon deployment with SwiftOnSecurity configuration for enhanced telemetry
Atomic Red Team integration for safe adversarial behavior simulation
Real-time dashboards, alerts, and correlation searches in Splunk
Detection of brute-force attacks, malicious PowerShell, and persistence techniques
Implementation Details
VirtualBox setup with Windows 10 (victim) and Ubuntu Server (SIEM) VMs
Splunk Enterprise installation and configuration on Ubuntu Server
Splunk Universal Forwarder and Sysmon deployment on Windows 10
Log ingestion verification and search functionality testing
Atomic Red Team attack simulation execution on Windows endpoint
Dashboard creation for threat visualization and monitoring
T1110 + T1078: Valid Accounts Used After Brute Force
T1059.001 + T1547.001: Multi-Stage Persistence with Scripting
Detection Use Cases
Suspicious PowerShell Execution detection and analysis
Brute Force Login Attempts monitoring and alerting
Registry Key Persistence technique identification
Brute Force followed by Successful Login correlation
PowerShell followed by Registry Persistence multi-stage detection
Splunk Features Implemented
Centralized log collection from Windows endpoints via Universal Forwarder
Real-time search and correlation capabilities with SPL queries
Custom dashboards for threat visualization and monitoring
Automated alerting for suspicious activities and IOCs
Saved searches and reports for ongoing threat hunting
Correlation logic for multi-stage attack detection
Key Outcomes
Enabled centralized log collection and comprehensive endpoint visibility
Successfully simulated real-world attacks aligned with MITRE ATT&CK framework
Developed robust detection content including dashboards, alerts, and SPL rules
Gained practical hands-on experience in SIEM deployment and detection engineering
PROJECT / 05RESEARCH
Remote Keylogger Research
Educational cybersecurity research project demonstrating keystroke logging techniques, steganography, and defensive countermeasures for security awareness.
Technologies Used
PythonPyInstallerSMTPSteganographyThreading
Key Highlights
Keystroke capture and logging
Remote data transmission via SMTP
Steganographic concealment techniques
Safety mechanisms and ethical considerations
Explore technical details
Technical Implementation
Cross-platform keystroke monitoring using pynput library
Secure SMTP transmission for remote data collection
File disguising as Windows system files (license_win64_details.txt)
Safety kill-switch via right control key for immediate termination
Host information gathering (IP, MAC, WiFi profiles, system details)
Threaded execution for seamless background operation
Implementation Details
GUI popup creation using tkinter for user interaction
Incremental data transmission at 500-byte file thresholds
PyInstaller compilation to standalone executable (.pyw extension)
WinRAR SFX archive packaging for steganographic deployment
Automatic cleanup and file deletion on program termination
Ethical Considerations
Developed strictly for educational and defensive security research
Includes built-in safety mechanisms to prevent misuse
Demonstrates attack vectors to improve defensive strategies
Used only in controlled environments with proper authorization
PowerShell CLI tool for hunting Windows malware persistence mechanisms and suspicious autoruns across Registry, Services, Scheduled Tasks, and Startup Items.