DEFENSIVE SECURITY · SYNTHETIC LAB

From telemetry
to incident report.

A reproducible Blue Team / SOC learning lab that models Windows security telemetry, detection engineering, investigation and response recommendations using safe simulated events.

LAB STATUSCONTROLLED & SIMULATEDNo real systems, credentials or customer data are used.

01 / END-TO-END WORKFLOW

Telemetry → detection → evidence.

01TelemetryWindows/Sysmon-style JSON events
→
02DetectionYAML rules and thresholds
→
03InvestigationEvidence timeline and triage
→
04ResponseMITRE mapping and report

02 / DETECTION USE CASES

Safe scenarios,
analyst-ready context.

HIGH

Repeated failed logons

Five failed authentication events against one account inside a ten-minute window.

BS-AUTH-001 · T1110
HIGH

Suspicious PowerShell

PowerShell process creation with a synthetic encoded-command marker.

BS-PS-001 · T1059.001
MEDIUM

Local account creation

A synthetic local account event requiring change validation and access review.

BS-ACC-001 · T1136.001
MEDIUM

Windows service creation

A service-change event that demonstrates persistence-oriented triage.

BS-SVC-001 · T1543.003

03 / INVESTIGATION METHOD

Evidence before conclusions.

Every alert carries its source events, host, account, timestamp, confidence, MITRE ATT&CK mapping, containment recommendation and remediation guidance.

✓ Validate the alert

✓ Reconstruct the timeline

✓ Record evidence and uncertainty

✓ Recommend safe containment

✓ Document hardening opportunities