Explore the experimental
SOC Homelab
by monitoring live.

Cybersecurity project by Ryan Mendenhall

Wazuh SIEM
providing overwatch.

  • Centralized logging & detection with Wazuh agents. Custom detection rules and MITRE ATT&CK mapping in progress.

Kali Linux instance
playing the attacker.

  • Nmap recon → vsftpd exploit → credential access → lateral movement. Real attack chains using Kali + Metasploitable.

Windows Pro, AD Server
and more as the victim.

  • Active Directory lab with Domain Controller and workstation. Realistic enterprise environment for detection engineering.

SOC Live Dashboard

This live dashboard provides a real-time window into the automated telemetry captured across your virtualized cybersecurity infrastructure. It aggregates threat intelligence from active Wazuh SIEM endpoints—tracking total event volume, classifying alerts by risk severity level, and mapping incoming security events directly to the MITRE ATT&CK framework. Designed to showcase automated endpoint protection and continuous threat monitoring, the feed highlights active attack vectors and system telemetry in real time.

Interactive Sandbox

Simulate a Level 12 Command & Control alert to see how the front-end SOC dashboard updates telemetry in real-time.

Event Volume (Last 24 Hours – UTC)

Live SOC Telemetry 4,801 Events

Severities
  • Level 31,781
  • Level 51,503
  • Level 71,275
  • Level 4154
  • Level 1037
Top MITRE Tactics
  • Defense Evasion 689
  • Privilege Escalation 349
  • Impact 318
Active Agents
  • WIN-QK6A1G7ET00 1,952
  • HomelabWindowsP 1,682
  • Homelab-Windows 564
Top Security Events
  • Name resolution for the name settings-win.data.microsoft.com timed out 567
  • Software protection service scheduled successfully. 353
  • Windows User Logoff 252
  • Windows Logon Success 248

Compliance Mapping

NIST Control Hits
  • Control CM.1 1,731
  • Control AU.14 671
  • Control AU.6 409
Top Event Categories
  • Windows 2,420
  • Sca 1,730
  • Windows_system 909
  • Windows_security 757

Telemetry Sources

Event Channels
  • EventChannel 2,420
  • sca 1,731
  • syscheck 407
  • journald 61
  • /var/log/audit/audit.log 50

SOC Live Dashboard

This live dashboard provides a real-time window into the automated telemetry captured across your virtualized cybersecurity infrastructure. It aggregates threat intelligence from active Wazuh SIEM endpoints—tracking total event volume, classifying alerts by risk severity level, and mapping incoming security events directly to the MITRE ATT&CK framework. Designed to showcase automated endpoint protection and continuous threat monitoring, the feed highlights active attack vectors and system telemetry in real time.

Interactive Sandbox

Simulate a Level 12 Command & Control alert to see how the front-end SOC dashboard updates telemetry in real-time.

Event Volume (Last 24 Hours – UTC)

Live SOC Telemetry 4,801 Events

Severities
  • Level 31,781
  • Level 51,503
  • Level 71,275
  • Level 4154
  • Level 1037
Top MITRE Tactics
  • Defense Evasion 689
  • Privilege Escalation 349
  • Impact 318
Active Agents
  • WIN-QK6A1G7ET00 1,952
  • HomelabWindowsP 1,682
  • Homelab-Windows 564
Top Security Events
  • Name resolution for the name settings-win.data.microsoft.com timed out 567
  • Software protection service scheduled successfully. 353
  • Windows User Logoff 252
  • Windows Logon Success 248

Compliance Mapping

NIST Control Hits
  • Control CM.1 1,731
  • Control AU.14 671
  • Control AU.6 409
Top Event Categories
  • Windows 2,420
  • Sca 1,730
  • Windows_system 909
  • Windows_security 757

Telemetry Sources

Event Channels
  • EventChannel 2,420
  • sca 1,731
  • syscheck 407
  • journald 61
  • /var/log/audit/audit.log 50
PROJECT GOAL

What is this project
and why is it underway?

Ascendant.design is a completely virtual Security Operations Center (SOC) home lab designed to replicate authentic cyber attack and defense environments. Hosted on VirtualBox, the setup encompasses four virtual machines connected via a segregated internal network. The architecture includes a Windows 11 Pro workstation, a Kali Linux system for offensive operations, a Metasploitable target machine, and a Wazuh SIEM server. Every simulated attack is aligned with the MITRE ATT&CK framework and actively monitored for detection through Wazuh.

// WHAT is the project?

The SOC Homelab is a series of 8 virtual machines. 1 VM serves as the Wazuh manager for SIEM overwatch. 1 VM is a version of Kali Linux, serving as a simulated attacker. The remaining VM's are various forms of Windows and Linux devices, including a Windows 2022 Server Active Directory instance, Windows Pro, and more.

// WHY is this project here?

The SOC Homelab serves as a important tool for me to continue to learn more about red team & blue team dynamics in a cybersecurity environment. It also serves as evidence of cybersecurity experience for resume purposes.

// HOW can I interact with it?

The data provided below is a live look-in at the current data being filtered through various logs, including the SIEM status, the status of its agents, the status of any simulated attacks, and more.

MY SETUP

Project Checklist

The following is an overview of the current virtual machine setup of the SOC Homelab: 

Wazuh SIEM Manager
Kali Linux Virtual Machine
Windows 2022 Active Dir
Ubuntu Linux Instance
Windows 11 Pro Instance
Windows 11 Home Instance

Snapshot look at the homelab project.

0
Live
agents
0
Simulated
attacks.
0
Open Vulnerabilities
to be patched.
0
Planned strategies
to implement.
WHAT WE FOUND

Brief highlights.

Here are some interesting highlights from the monitoring of our virtual machine environments and the SIEM itself. Stay tuned for more information coming soon!

Expected Project Completion by End of Month
0%
0 %
Current Project completion

As tracked through Notion Project.

Discoveries

Interesting finds from the Wazuh SIEM and red team simulations from the Kali Linux VM.

Data Tracked

Capture user behavior across mobile apps and web properties for precise attribution.

Malware Blocked

Ensure that no malware can corrupt and compromise the victim virtual machines.

Vulnerabilities Squashed

Prevent malicious activity and ensure you only pay for high-quality, authentic results.

Live Protection

How we defended our systems when under various red team simulations and how we responded.

Monitor & Track

Generated reports that help you to visualize trends and make informed, data-driven decisions.