Suricata Network IDS
Tools: Suricata, tcpdump, Wireshark
Signature and anomaly-based detection lab monitoring simulated traffic in real time.
Demonstration of IDS systems, attack simulations, and infrastructure setups.
Tools: Suricata, tcpdump, Wireshark
Signature and anomaly-based detection lab monitoring simulated traffic in real time.
Tools: Snort, PCAP replay
Custom detection rules tested against known attack traffic samples.
Tools: Burp Suite, OWASP ZAP
Exploitation attempts covering OWASP Top 10 categories against an isolated test target.
Tools: GoPhish, custom templates
Controlled phishing campaign to assess user awareness and email filtering.
Tools: Suricata, EveBox, Filebeat, Elasticsearch, Node Exporter, Prometheus, Promtail, Loki, Grafana, Caddy
Suricata inspects all inbound traffic and emits alerts only (eve.json) β forwarded to EveBox for analyst triage and to Elasticsearch via Filebeat. System metrics and logs flow through Prometheus/Promtail into Loki and Grafana for a live SOC dashboard, served over HTTPS via Caddy.
Internet
β
Suricata
β
eve.json (alerts only)
β
βββββββββββββββββ΄ββββββββββββββββ
β β
EveBox Filebeat
(alert analyst UI) β
βΌ
Elasticsearch
(alerts only)
Node Exporter βββΆ Prometheus βββ
β
System logs ββΆ Promtail ββΆ Loki β€
βΌ
Grafana
(LIVE SOC Dashboard)
β
Caddy
(HTTPS access)
Tools: pfSense, VLANs, virtualization
VLAN-based network segmentation isolating attacker, target, and monitoring zones.
Tools: Proxmox/VirtualBox, ELK stack
Self-hosted monitoring and log aggregation stack for lab telemetry.
First line of defense β filters traffic at the network perimeter based on rules and zones.
Inspects HTTP/S traffic to block common web attacks (SQLi, XSS, and more) before they reach the application.
Monitors and blocks malicious network activity that bypasses the perimeter.
Provides host-level visibility and response for threats that reach endpoints.
Centralizes logs across all layers for correlation, alerting, and incident response.
Protects the physical medium and physical access to equipment.
Protects frames, MAC addresses, and switching.
Protects routing and IP traffic.
Protects TCP/UDP sessions and ports.
Protects session establishment and management.
Protects data format, encryption, and encoding.
Protects the applications themselves and top-level protocols.