Explore the experimental
SOC Homelab
by monitoring live.

Cybersecurity project by Ryan Mendenhall

Wazuh SIEM
providing overwatch.

  • Centralized logging & detection with Wazuh agents. Custom detection rules and MITRE ATT&CK mapping in progress.

Kali Linux instance
playing the attacker.

  • Nmap recon → vsftpd exploit → credential access → lateral movement. Real attack chains using Kali + Metasploitable.

Windows Pro, AD Server
and more as the victim.

  • Active Directory lab with Domain Controller and workstation. Realistic enterprise environment for detection engineering.

Wazuh SIEM Endpoints

Alternate between each endpoint via the dropdown menu in the top left of the dashboard. Interact with any section below to see the SIEM in greater detail.
W./Endpoints/
Last Keep-alive: Oct 6, 2026 @ 18:29:51 UTC
Status
Active
IP Address
192.168.128.7
Version
Wazuh v4.14.7
Cluster Node
node01
Operating System
Microsoft Windows 11 Pro
System Inventory
vCPUs
2 Cores
Memory
4GB RAM
Processor
Intel(R) Core(TM) i7-14700K
Hostname
WINDOWS-11-PRO
OS Build
10.0.26200.8037
Events Count Evolution Past 24 Hours
MITRE ATT&CK Top Tactics
Execution3
Impact2
Defense Evasion1
Compliance
Vulnerability Detection
Critical107
High1,294
Medium616
Low57
Top 4 Vulnerable Packages
Microsoft Windows 11 Pro 10.0.26200.80371,480
Google Chrome568
Microsoft Edge13
Microsoft Edge WebView2 Runtime13
Security Configuration Assessment (SCA)
Policy NamePassedFailedScore
CIS Microsoft Windows 11 Enterprise Benchmark v3.0.012534826%
Passed: 125 (26%) Failed: 348 (74%)

SOC Live Dashboard

This live dashboard provides a real-time window into the automated telemetry captured across your virtualized cybersecurity infrastructure. It aggregates threat intelligence from active Wazuh SIEM endpoints—tracking total event volume, classifying alerts by risk severity level, and mapping incoming security events directly to the MITRE ATT&CK framework. Designed to showcase automated endpoint protection and continuous threat monitoring, the feed highlights active attack vectors and system telemetry in real time.

Interactive Sandbox

Simulate a Level 12 Command & Control alert to see how the front-end SOC dashboard updates telemetry in real-time.

Event Volume (Last 24 Hours – UTC)

Live SOC Telemetry 10,000 Events

Severities
  • Level 57,704
  • Level 34,483
  • Level 72,779
  • Level 4335
  • Level 9106
Top MITRE Tactics
  • Defense Evasion 6,834
  • Impact 2,626
  • Privilege Escalation 998
Active Agents
  • Windows-11-Pro 4,929
  • WIN-BACJJ5JI7U9 3,721
  • HomelabWindowsP 1,985
Top Security Events
  • Registry Value Entry Added to the System 2,541
  • Software protection service scheduled successfully. 1,639
  • Registry Value Integrity Checksum Changed 1,593
  • Host-based anomaly detection event (rootcheck). 1,020

Compliance Mapping

NIST Control Hits
  • Control SI.7 5,940
  • Control CM.1 2,334
  • Control AU.14 1,167
Top Event Categories
  • Ossec 7,192
  • Syscheck 5,940
  • Syscheck_registry 5,791
  • Windows 4,625

Telemetry Sources

Event Channels
  • syscheck 5,940
  • EventChannel 4,632
  • sca 2,336
  • journald 1,157
  • rootcheck 1,020

SOC Live Dashboard

This live dashboard provides a real-time window into the automated telemetry captured across your virtualized cybersecurity infrastructure. It aggregates threat intelligence from active Wazuh SIEM endpoints—tracking total event volume, classifying alerts by risk severity level, and mapping incoming security events directly to the MITRE ATT&CK framework. Designed to showcase automated endpoint protection and continuous threat monitoring, the feed highlights active attack vectors and system telemetry in real time.

Interactive Sandbox

Simulate a Level 12 Command & Control alert to see how the front-end SOC dashboard updates telemetry in real-time.

Event Volume (Last 24 Hours – UTC)

Live SOC Telemetry 10,000 Events

Severities
  • Level 57,704
  • Level 34,483
  • Level 72,779
  • Level 4335
  • Level 9106
Top MITRE Tactics
  • Defense Evasion 6,834
  • Impact 2,626
  • Privilege Escalation 998
Active Agents
  • Windows-11-Pro 4,929
  • WIN-BACJJ5JI7U9 3,721
  • HomelabWindowsP 1,985
Top Security Events
  • Registry Value Entry Added to the System 2,541
  • Software protection service scheduled successfully. 1,639
  • Registry Value Integrity Checksum Changed 1,593
  • Host-based anomaly detection event (rootcheck). 1,020

Compliance Mapping

NIST Control Hits
  • Control SI.7 5,940
  • Control CM.1 2,334
  • Control AU.14 1,167
Top Event Categories
  • Ossec 7,192
  • Syscheck 5,940
  • Syscheck_registry 5,791
  • Windows 4,625

Telemetry Sources

Event Channels
  • syscheck 5,940
  • EventChannel 4,632
  • sca 2,336
  • journald 1,157
  • rootcheck 1,020
PROJECT GOAL

What is this project
and why is it underway?

Ascendant.design is a completely virtual Security Operations Center (SOC) home lab designed to replicate authentic cyber attack and defense environments. Hosted on VirtualBox, the setup encompasses four virtual machines connected via a segregated internal network. The architecture includes a Windows 11 Pro workstation, a Kali Linux system for offensive operations, a Metasploitable target machine, and a Wazuh SIEM server. Every simulated attack is aligned with the MITRE ATT&CK framework and actively monitored for detection through Wazuh.

// WHAT is the project?

The SOC Homelab is a series of 8 virtual machines. 1 VM serves as the Wazuh manager for SIEM overwatch. 1 VM is a version of Kali Linux, serving as a simulated attacker. The remaining VM's are various forms of Windows and Linux devices, including a Windows 2022 Server Active Directory instance, Windows Pro, and more.

// WHY is this project here?

The SOC Homelab serves as a important tool for me to continue to learn more about red team & blue team dynamics in a cybersecurity environment. It also serves as evidence of cybersecurity experience for resume purposes.

// HOW can I interact with it?

The data provided below is a live look-in at the current data being filtered through various logs, including the SIEM status, the status of its agents, the status of any simulated attacks, and more.

MY SETUP

Project Checklist

The following is an overview of the current virtual machine setup of the SOC Homelab: 

Wazuh SIEM Manager
Kali Linux Virtual Machine
Windows 2022 Active Directory
Ubuntu Linux Instance
Windows 11 Pro Instance

Snapshot look at the homelab project.

0
Live
agents
0
Simulated
attacks.
0
Open Vulnerabilities
to be patched.
0
Planned strategies
to implement.
WHAT WE FOUND

Brief highlights.

Here are some interesting highlights from the monitoring of our virtual machine environments and the SIEM itself. Stay tuned for more information coming soon!

Expected Project Completion by End of Month
0%
0 %
Current Project completion

As tracked through Notion Project.

Discoveries

Interesting finds from the Wazuh SIEM and red team simulations from the Kali Linux VM.

Data Tracked

Capture user behavior across mobile apps and web properties for precise attribution.

Malware Blocked

Ensure that no malware can corrupt and compromise the victim virtual machines.

Vulnerabilities Squashed

Prevent malicious activity and ensure you only pay for high-quality, authentic results.

Live Protection

How we defended our systems when under various red team simulations and how we responded.

Monitor & Track

Generated reports that help you to visualize trends and make informed, data-driven decisions.