This project demonstrates the design, deployment, and validation of a Virtual Security Operations Centre (SOC) lab using open-source security tools.
The lab objective was to:
- Deploy a Network Intrusion Detection System (Suricata)
- Integrate it with a SIEM platform (Elastic Stack)
- Simulate reconnaissance attacks
- Detect, forward, and visualize security alerts
- Validate an end-to-end threat detection workflow
The lab successfully detects reconnaissance scans (for example, Nmap SYN scans) and visualizes alerts in Kibana.
- Configure a secure virtual network environment
- Deploy Suricata as a network IDS
- Enable and manage threat detection rules
- Simulate attack traffic from an attacker VM
- Forward IDS logs to Elasticsearch using Filebeat
- Visualize and analyze alerts in Kibana
- Validate real-time detection capability
- Attacker VM generates malicious or test network traffic.
- Suricata IDS server monitors traffic and writes alerts/logs.
- Filebeat collects Suricata logs and ships them to Elasticsearch.
- Elasticsearch indexes and stores security events.
- Kibana visualizes events for investigation and monitoring.
- OS: Ubuntu 24.04
- Tool: Nmap
- Role: Simulate reconnaissance attacks
- OS: Ubuntu 24.04
- Suricata
- Elasticsearch 8.x
- Kibana 8.x
- Filebeat
- Oracle VirtualBox
- Host-Only Networking mode
- Network range:
192.168.56.0/24
- RAM: 15 GB
- OS: Ubuntu 24.04 LTS
- Monitored interface:
enp0s8
- RAM: 10 GB
- OS: Ubuntu 24.04 LTS
- Adapter 1: Host-Only Adapter (Promiscuous Mode enabled)
- Adapter 2: NAT (internet access for package downloads)
- IDS Server:
192.168.56.103 - Attacker VM:
192.168.56.102
ping 192.168.56.103
tcpdump -i enp0s8sudo apt update
sudo apt install suricata -yEnabled Emerging Threats Open ruleset:
sudo suricata-update enable-source et/open
sudo suricata-update update-sources
sudo suricata-updateLoaded rules: ~48,000+ detection rules.
Configured Suricata to monitor enp0s8.
Verification:
sudo suricata -T -c /etc/suricata/suricata.yaml -i enp0s8sudo systemctl status suricataConfirmed active and running.
Attack traffic generated from attacker VM:
nmap -sS 192.168.56.103
nmap -A 192.168.56.103- ET SCAN NMAP OS Detection Probe
- TCP SYN scan patterns
- Reconnaissance alerts
Verified alerts in:
/var/log/suricata/fast.log/var/log/suricata/eve.json
Configured as a single-node cluster:
discovery.type: single-nodeVerified cluster status:
curl -k -u elastic:<password> https://localhost:9200Cluster returned a healthy response.
Connected to Elasticsearch using an enrollment token.
Verified access via:
http://192.168.56.103:5601
Created data view:
filebeat-*
sudo filebeat modules enable suricataEnabled eve fileset:
enabled: true
var.paths: ["/var/log/suricata/eve.json"]sudo filebeat setupsudo systemctl enable filebeat
sudo systemctl start filebeatVerified ingestion:
sudo filebeat test outputConfirmed full pipeline:
- Nmap scan executed
- Suricata generated alert
eve.jsonupdated- Filebeat forwarded log
- Elasticsearch indexed event
- Kibana displayed detection
Example alert:
- ET SCAN NMAP OS Detection Probe
Mapped to MITRE ATT&CK:
-
T1595 - Active Scanning
-
T1046 - Network Service Scanning
-
Severity: Medium
-
Classification: Attempted Information Leak
Issues resolved during setup:
- Suricata interface mismatch
- Missing ruleset loading
- Elasticsearch bootstrap error
- Kibana authentication issue
- Filebeat module misconfiguration (eve fileset disabled)
Diagnosis commands used:
systemctl status <service>
journalctl -u <service>- Network configuration
- IDS deployment and rule management
- SIEM integration
- Log pipeline troubleshooting
- Threat detection validation
- Elastic security architecture
Successfully implemented a working SOC lab capable of:
- Detecting reconnaissance attacks
- Centralizing IDS logs
- Visualizing security events
- Performing initial threat investigation
This lab simulates real-world SOC infrastructure used in enterprise environments.
- Add Zeek for network analysis
- Add Wazuh for host-based detection
- Create automated detection rules in Kibana
- Build custom dashboards
- Implement alert email notifications
- Deploy using Docker

















