Menu
ls111's Cybersecurity Blog
  • Home
  • Contact
ls111's Cybersecurity Blog

Intro to Cyber Security Operations (SOC) – Blue vs Red Team – Virtual Lab Building Series: Ep8

Posted on May 27, 2022September 19, 2023 by wp_writer

In Episode 8 of our cyber security virtual lab building series, we set the stage and some future goals as to where we are heading with this series. We briefly recap the first 7 videos, showcasing OPNSense and introduce both blue team and read team cyber security operations into our lab.

For our cybersecurity blue team, we will building a Security Operations Center (SOC) and setup Wazuh as a SIEM (Security Incident & Event Management) platform, integrating in The HIVE, a SIRP (Security Incident Response Platform) which will facilitate or security event case management. In addition to this, cases created in The HIVE will be fed into Cortex a powerful observables analysis and active response engine, which compares intelligence against MISP and other analyzers to determine an active response. Later, we will be integrating all of the above to create a SOAR (Security Orchestration, Automation and Response) system, which through automation takes some of the load away from the security team.

Moving over to our cybersecurity red team operations, we will configure CALDERA, a automated adversary emulation framework that allows us to simulate the various attacks and techniques listed in the MITER ATT&CK framework.

Our endpoints being a Windows Server, Ubuntu Server and Windows 10 Pro desktop will be installed with the Wazuh EDR/XDR agent which will report to and respond to any security events to the SIEM.

The ultimate goal of this series to to look at both the cyber security blue team and red team perspectives and understand how to attack and defend, providing you with take away skills that you can use in real world scenarios to strengthen your overall cyber security posture. If you have been enjoying this series so far, please don’t forget to like and subscribe!

Links used in this lab:

  • https://thehive-project.org/
  • https://d3fend.mitre.org/
  • https://wazuh.com/
  • https://attack.mitre.org/
  • https://github.com/mitre/caldera

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Welcome to my blog! I discuss and showcase various cybersecurity topics. If you prefer to learn through watching video, please check out my YouTube channel, most of the content here also has a video version.

YouTube Channel
GitHub

Search by Category

  • Active Directory
  • Blue Team/Defensive
  • Cyber Security Lab Building Series
  • datadog
  • docker
  • Elasticsearch
  • General Cybersecurity
  • Kibana
  • Logstash
  • Network Security
  • OPNSense Firewall
  • Red Team/Pen Testing
  • SASE
  • Security Compliance
  • SIEM
  • Splunk Enterprise
  • TryHackMe Labs
  • Ubuntu Linux
  • Virtualization
  • Wazuh SIEM & XDR
  • Zenarmor NGFW

Search by Date

  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • December 2022
  • October 2022
  • September 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
©2025 ls111's Cybersecurity Blog | Powered by Superb Themes