Detection Engineering Lab – Cowrie Honeypot + ELK Stack
• Deployed Cowrie SSH honeypot with Filebeat and Elasticsearch to capture attacker activity. • Simulated brute-force activity and developed KQL-based detections for authentication and command execution. • Analyzed attacker behavior and mapped activity to MITRE ATT&CK for SOC-style investigation.
Active Directory Attack & Detection Engineering Lab
• Simulated Active Directory attack techniques including enumeration, password spraying, Kerberoasting, privilege escalation, and lateral movement. • Used CrackMapExec, Impacket, and BloodHound to replicate adversary behavior and validate detection coverage. • Built network-based detections using Suricata and integrated telemetry with Raspberry Pi, Loki, and Grafana. • Developed detection rules and mapped activity to MITRE ATT&CK to support threat hunting