Linux Network Telemetry Dashboard
Was about to run port scans. Realized I should watch them land
first.
- Splunk doesn't pre-build dashboards — you build what you care
about
- RIGGS (claude code) automated the config: kernel-level auditd rules + Splunk
monitor stanza
- Dashboard: Baseline → Detect → Investigate
Need a few days for a real baseline. Scans hit the detect panels
in real time when I run them.
SOC Lab Day 6 - Trust But Verify
Laptop on cafe WiFi. Ran tcpdump on the WiFi interface while SSHing to the lab. Post-capture awk filter to cut the noise.
What the "attacker" saw:
- All UDP — no TCP, no port 22
- Encrypted blobs — no readable data
- One port 1028 anomaly (Tailscale path discovery, expected)
Tunnel is G2G.
SOC Lab Day 5 - First Real Alert Landed
Ran Atomic Red Team T1003.001 against my Windows 11 target:
LSASS dump via ProcDump.
Defender fought back hard. Had to clear execution policy, exclusions, Tamper Protection, LSASS PPL, and SSH admin token issues.
Then it ran.
19 events hit Splunk.
SIEM caught the chain.
Pipeline verified.
SOC Lab Day 4 - The First Windows Target Joined the Lab!
What went into today:
- Navigated two cloud dead-ends mid-build. GCP credits expired, AWS verification locked us out for 3–5 days. Pivoted to a local KVM setup rather than wait.
- Provisioned Windows 11 Enterprise Evaluation on KVM/QEMU — running headless on Miggs, accessed via VNC over an SSH tunnel
- Completed OOBE as a local account. The path around Microsoft's sign-in push is labeled "domain join instead" — ironic, given what's planned for this machine
- Turned every privacy toggle off. The goal is a clean Sysmon baseline. Microsoft phoning home is noise on the wire
SOC Lab Day 3 - Foundations and Secret Shards
Today I:
- Hardened the host before building on top of it
- Isolated and verified the lab foundation
- Set up secrets management with recovery tested
Nothing flashy.
SOC Lab Day 2 — Grok’n
I wanted to start building the lab immediately.
Instead, I spent a few hours breaking the architecture apart and learning what each piece actually does:
Splunk Attack Range
Wazuh
TheHive
Cortex
MISP
Workflow:
YouTube → conceptual overview
Claude → pressure-test my understanding
Web docs → edge cases and details
Notebook → sketch it out or write it in my own words
Less exciting than spinning up VMs, but probably the right move.
SOC Lab Day 1 — The Plan
I’m studying for Security+, but I don’t want this to stay theoretical.
So I’m building a home SOC lab to practice the full analyst loop:
attack → collect telemetry → detect → investigate → create case → respond → document
Initial stack:
Kali + Atomic Red Team +PurpleSharp
Windows Server DC + Win10 endpoint
Sysmon + Splunk + Wazuh
TheHive + Cortex
Claude in the analyst loop for research, documentation, and writing support
Goal: build this in phases, verify each layer against industry docs/best pratices, then start running realistic detections.
Day 1 is the map.
Next step: build the foundation.
Started using a simple scratchpad workflow at the end of each day to quickly route notes, tasks, todos, random thoughts etc.
The 4 option triage is my favorite aspect. It presents each item with 4 similarly recurring options.
1 = complete now
2 = complete small step now
3 = keep in scratchpad for 1 more day
4 = delete
Whats nice is if the task is related to a ongoing project my model picks up on that context and tailors the 4 options.
That is the real value:
Catching the spiral early.
Once in the morning.
Again before bed, if I’m disciplined.
Old-school practice.
New-school feedback loop.
The current MVP only uses Marcus Aurelius’ Meditations.
Nine times out of ten, it lands.
Not because it replaces reflection.
Because it gives reflection better timing.
You are valuable to these companies.
That is why they are asking for more than your resume.
Slow down.
Read the terms.
Use AI to inspect the agreement before you accept it.
Be aware.
Be picky.
Your likeness is a commodity.
I was applying to an AI-training contract role today.
$30–60/hr.
Remote.
Security analyst work.
Before accepting the terms, I had my AI read the agreement.
Good thing I did.
This has the same smell as the old Google/Facebook data siphoning era.
Only now the asset is more personal.
Not just your clicks.
Not just your browsing.
Not just your attention.
Your face.
Your voice.
Your likeness.