Return to Portfolio

Project Detail

Wazuh SIEM Home Lab

Centralized monitoring, alerting, and threat detection lab

Designed and deployed a Wazuh-based SIEM home lab featuring centralized logging, Active Directory integration, endpoint monitoring, threat hunting dashboards, and custom alerting workflows.

Overview

Project Overview

This project simulated a real-world enterprise environment by integrating centralized logging, endpoint monitoring, Active Directory infrastructure, Windows and Linux systems, and custom alerting workflows into a unified security operations environment.

Core Technologies

  • Wazuh SIEM
  • Windows Server
  • Active Directory
  • Microsoft 365
  • Linux Administration
  • Endpoint Monitoring Agents
  • Slack Alert Integration
  • CSV Log Exporting and Analysis

Security Operations Experience

  • Centralized log monitoring and analysis.
  • Threat hunting across Windows and Linux systems.
  • Custom alert and trigger configuration.
  • Endpoint visibility and event investigation.
  • Detection of suspicious login activity.
  • SIEM dashboard creation and monitoring.
  • Incident investigation workflows.
  • Security event exporting and reporting.

Infrastructure Components

  • 2 Domain Controllers (DC01 / DC02).
  • File server infrastructure.
  • Database server environment.
  • 16 Windows client systems.
  • Wazuh SIEM server.
  • Domain authentication environment.
  • Centralized endpoint monitoring.

Simulated Security Operations Console

[INFO] Wazuh agents connected successfully

[EVENT] Windows login detected from WORKSTATION-03

[WARNING] Multiple failed login attempts detected

[EVENT] Threat hunting dashboard updated

[EVENT] Exporting logs to CSV for offline analysis

[ALERT] Brute Force Alert triggered

[ACTION] Slack notification sent to security channel

[INFO] Endpoint monitoring active across all systems

Architecture

Environment Architecture

The environment was designed to simulate an enterprise network with centralized authentication, endpoint visibility, and SIEM-driven monitoring capabilities.

Active Directory

Centralized user authentication and domain management.

Wazuh SIEM

Centralized log collection and threat monitoring.

Endpoints

Windows and Linux systems monitored through agents.

Alerting

Custom alerts and Slack notification integration.

Implementation

Example Detection Workflow

1. Endpoint generates security event
2. Wazuh agent forwards event to SIEM server
3. SIEM parses and analyzes event logs
4. Threat hunting dashboard updates automatically
5. Detection rules evaluate suspicious activity
6. Custom monitor triggers alert
7. Slack notification sent to security channel
8. Analyst investigates event and exported logs