学习安全运营的记录 | The knowledge base of security operation
-
Updated
Aug 27, 2023 - HTML
学习安全运营的记录 | The knowledge base of security operation
常见的攻击行为监测特征及方法,涵盖端点和流量,未包含PowerShell和Sysmon。预祝运营生活愉快!
Hands-on Azure SOC simulation project focused on Microsoft Sentinel, threat detection engineering, log ingestion pipelines, KQL-based analytics, custom telemetry onboarding, and real-world SOC monitoring workflows using Windows & Linux virtual machines.
Terraform-based Azure SOC infrastructure deploying Windows Server 2025, Log Analytics, Azure Monitor Agent, and Data Collection Rules for Microsoft Sentinel.
This project was created to meet the requirements of my major project
A Real-time SOC platform for centralized monitoring, threat response, and geospatial insights via Atlas.
End-to-end IT Support + Security Operations lab on AWS Free Tier. Helpdesk (osTicket), IAM, CloudTrail, incident detection and response. USD $0 cost.
Python script to generate network traffic
End-to-end SOC detection lab simulating ELK-based monitoring, log ingestion, security event detection, and incident investigation across Windows and Linux environments.
Add a description, image, and links to the security-operation topic page so that developers can more easily learn about it.
To associate your repository with the security-operation topic, visit your repo's landing page and select "manage topics."