Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Enterprise SOC Detection Platform

Executive Summary

This project simulates an enterprise-grade Security Operations Center (SOC) environment designed to detect, investigate, and triage large-scale security events across authentication, endpoint, and system telemetry sources.

The platform ingests high-volume simulated security logs and applies correlation-based detection logic to identify brute-force authentication attempts, privilege escalation events, encoded PowerShell execution, suspicious process behavior, and attacker lateral movement.


Objectives

  • Simulate enterprise-scale security telemetry ingestion
  • Detect malicious behavioral indicators
  • Investigate suspicious activity using SIEM correlation searches
  • Generate incident timelines
  • Produce analyst investigation reports

Technologies Used

  • Splunk Enterprise
  • Python
  • Sysmon
  • Sigma Detection Rules
  • Security Event Correlation

About

Enterprise-scale SOC simulation for threat detection, SIEM investigation, incident triage, and security telemetry analysis.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors