Building a Production-Grade SOC: A Wazuh Lab Series

Lab 01: Building a Home SOC Environment

A practical case study documenting the deployment, troubleshooting, and configuration of a Wazuh-based SOC lab using constrained hardware and virtualized infrastructure.

Lab 02: File Integrity Monitoring Configuration

Configuring and testing Wazuh's File Integrity Monitoring across Windows and Linux agents, and applying a tiered monitoring strategy that reflects real SOC practices.

Lab 03: Brute Force and Credential Stuffing Detection

Simulating brute force and credential stuffing attacks against Linux and Windows agents, analysing Wazuh's default detection behaviour, and examining how the results map to the MITRE ATT&CK framework.

Lab 04: Windows Security Telemetry Engineering

Deploying PowerShell logging and Sysmon alongside existing Security and System telemetry, then using a single controlled trigger to compare what each Windows telemetry source actually reveals — and what it misses.

Lab 05: Custom Detection Rule Engineering

Writing custom Wazuh correlation rules to detect cross-username credential stuffing on Linux and Windows, closing the detection gap identified in Lab 03.

Lab 06: False Positive Reduction and Detection Tuning

Tuning custom credential stuffing rules to stop re-firing on every qualifying event, and discovering that the fix solved alert volume without touching a separate, still-unresolved rule-suppression bug.

Lab 07: MITRE ATT&CK Coverage Analysis

Auditing declared MITRE ATT&CK coverage against what has actually been validated in this environment, and resolving two carry-forward findings from Labs 05 and 06 along the way — one successfully, one not.