← All projects

CASE STUDY / DETECTION ENGINEERING

From endpoint telemetry
to threat detection

Building a SIEM lab with Splunk & Atomic Red Team.

A hands-on Security Operations Center lab connecting Windows endpoint activity to centralized investigation, ATT&CK-aligned detections, and real-time alerting.

Explore the GitHub repository ↗
ENVIRONMENTVirtualBox home lab
FOCUSDetection engineering
CORE STACKSplunk · Sysmon · Atomic Red Team

01 / OBJECTIVE

Make simulated attacker activity visible.

The goal was to build a small SOC environment that could collect endpoint logs, surface suspicious activity, and connect individual events into meaningful attack sequences. The lab covers the path from telemetry collection through detection and investigation.

02 / LAB ARCHITECTURE

One endpoint. Centralized visibility.

Lab architecture / logical data flow
SIMULATE

Atomic Red Team

Controlled adversarial behavior on the Windows endpoint

COLLECT & FORWARD

Windows 10

Sysmon + Splunk Universal Forwarder

ANALYZE & ALERT

Ubuntu Server

Splunk Enterprise, dashboards, and correlation searches

Both virtual machines run in VirtualBox. This diagram illustrates the lab setup; it is not a captured dashboard.

03 / IMPLEMENTATION

What I built.

  1. Provisioned the lab

    Set up Windows 10 as the target endpoint and Ubuntu Server as the host for Splunk Enterprise.

  2. Connected endpoint telemetry

    Deployed Sysmon with the SwiftOnSecurity configuration and installed Splunk Universal Forwarder. Verified log ingestion and search functionality.

  3. Simulated adversarial behavior

    Used Atomic Red Team to exercise attack techniques in the lab and map the resulting activity to the MITRE ATT&CK framework.

  4. Built detection content

    Created dashboards, alerts, SPL searches, and correlation logic for individual techniques and multi-stage activity.

04 / DETECTION SCENARIOS

From single events to attack sequences.

T1059.001

Suspicious PowerShell

Detection and analysis of suspicious PowerShell execution on the Windows endpoint.

T1110.001

Password guessing

Monitoring and alerting for repeated login attempts associated with brute-force activity.

T1547.001

Registry persistence

Identification of registry-based boot or logon autostart persistence.

T1110 + T1078

Failures followed by success

Correlation of brute-force activity with a subsequent successful login using a valid account.

T1059.001 + T1547.001

Scripting followed by persistence

Correlation of PowerShell activity with registry persistence to identify a multi-stage sequence.

05 / OUTCOMES

A working foundation for threat detection.

Scope: a controlled lab project. These outcomes describe the implementation; they do not establish production detection coverage or measured accuracy.

06 / TAKEAWAYS

Collection, context, correlation.

The workflow brings three parts of detection engineering together: collecting useful endpoint telemetry, understanding the behavior behind an event, and correlating related activity. The multi-stage scenarios show why a sequence of events can provide more context than an isolated alert.