Skip to content

A cybersecurity lab simulating real-world threat detection using Hydra brute-force, Wireshark traffic capture, Wazuh SIEM, and pfSense firewall segmentation — showcasing incident detection, response, and network hardening workflows.

Notifications You must be signed in to change notification settings

Dekiridi/SOC-Threat-Detection-Log-Analysis-Lab-Wazuh-Hydra-Wireshark

Repository files navigation

SOC Detection Lab: Hydra, Wireshark, Wazuh, pfSense

🚀 Career Pivot in Action: From Banking & Finance to SOC Analyst

This repository contains artifacts from a hands-on cybersecurity capstone project aimed at simulating and detecting network threats in a controlled environment. The project showcases a complete detection and defense workflow using industry-standard tools.


🔍 Project Overview

Goal: Build a realistic SOC (Security Operations Center) lab to detect and respond to brute-force SSH attacks, enhancing cybersecurity skills in threat detection, network security, and incident response.


🛠️ Tools Used

  • Wireshark – for network traffic capture and analysis 📊
  • Hydra – for controlled SSH brute-force attack simulations 🛠️
  • Wazuh SIEM (v4.11.1) – for real-time security monitoring and threat detection ⚡
  • pfSense – for firewall protection and network segmentation 🔐
  • VirtualBox – for lab virtualization and network isolation 🖥️

📈 Lab Workflow

  1. Capture baseline traffic using Wireshark.
  2. Simulate brute-force attack on SSH with Hydra.
  3. Detect and alert on suspicious activity with Wazuh.
  4. Implement network hardening with pfSense.
  5. Analyze network events and translate findings into business risk language.

🌟 Key Takeaways

  • Risk-Management Mindset + Security Tooling = Stronger Defenses.
  • Logs are the New Ledgers – turn network data into actionable insight.
  • Growth Happens Outside Comfort Zones – curiosity fuels continuous learning.

let's connect

🔗 LinkedIn 📧 Email


📸 Project Screenshots

Performing a brute-force attack captured in the lab:

Brute Force Attack

Traffic Capture with Wireshark:

Wireshark Traffic Capture

Wazuh SIEM Detection and Correlation:

Wazuh SIEM Alert


🎯 Outcome

This project honed my skills in:

  • Network architecture and segmentation.
  • Traffic analysis and security event correlation.
  • Translating technical findings into business risk language.
  • Real-world incident detection and response simulation.

"Logs are the new ledgers—turn them into actionable insight."

About

A cybersecurity lab simulating real-world threat detection using Hydra brute-force, Wireshark traffic capture, Wazuh SIEM, and pfSense firewall segmentation — showcasing incident detection, response, and network hardening workflows.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published