
2.2M
0Xsoc/threat-hunting related:
1.SSH Brute-Force Detection in Splunk
Simulate SSH brute-force attacks and build Splunk dashboards with threshold-based alerts to detect credential abuse patterns.
Tech: Kali, Metasploit, Nmap, Splunk, auth.log
2.Port Scan Detection Engineering Lab
Perform multiple Nmap scan types and create SIEM queries to detect reconnaissance while reducing false positives.
Tech: Kali, Nmap, Splunk or ELK
3.Reverse Shell Network Detection Study
Generate reverse shells and analyze packet captures to identify abnormal outbound connections and suspicious ports.
Tech: Kali, Netcat, Metasploit, Wireshark
4.End-to-End SOC Investigation Simulation
Execute a full attack chain (scan, exploit, shell) and produce a structured incident timeline with detection evidence.
Tech: Kali, Nmap, Metasploit, Wireshark, Splunk or ELK
5.Custom Log-Based Intrusion Detection Script
Develop a Python or Bash script to detect brute-force patterns in Linux logs and forward structured alerts to a SIEM.
Tech: Kali, Python or Bash, Splunk or ELK
6.Beaconing Traffic Detection Lab
Simulate periodic command-and-control traffic and build time-based detection logic to identify beaconing behavior.
Tech: Kali, Netcat, Wireshark, Splunk or ELK
7.Exploitation Visibility Analysis
Exploit a vulnerable service and compare raw log visibility versus SIEM detection coverage to identify monitoring gaps.
Tech: Kali, Metasploit, Splunk or ELK
8.Web Attack Detection in SIEM
Simulate common web attacks and create detection queries for suspicious parameters, error spikes, and encoded payloads.
Tech: Kali, Metasploit, Splunk or ELK
9.Network Baseline vs Attack Deviation Report
Capture normal traffic, introduce attacks, and document behavioral differences in packet flow and port usage.
Tech: Kali, Wireshark, Nmap, Splunk or ELK
10.Detection Rule Tuning & False Positive Reduction
Build initial detection rules for scans and brute-force activity, then refine them to balance accuracy and noise reduction.
Tech: Kali, Nmap, Metasploit, Splunk or ELK
#project #cybersecurity #soc #kali #wireshark
@0xpvee










