// SOC Home Lab Environment

CYBEROPS LAB

VIRTUALBOX · BRIDGE NETWORK · WAZUH SIEM · DVWA
WAZUH SIEM ACTIVE
ATTACKER NODE LIVE
DVWA RUNNING
UFW FIREWALL ON
◈ VIRTUALBOX BRIDGE NETWORK
192.168.1.0/24
🐉
KALI LINUX
ATTACKER NODE
192.168.1.16
Nmap / Recon Metasploit SQLmap Hydra Nikto Burp Suite Wazuh Agent Kali Tools Suite
🛡️
UBUNTU SERVER
DEFENDER + SOC NODE
192.168.1.X
Wazuh Server Wazuh Indexer Wazuh Manager DVWA (Apache) UFW Firewall MySQL / PHP Log Analysis Alert Monitoring
⟷   VirtualBox Bridge Network   ⟷
Both VMs share host network adapter · Real IP assignment · Realistic traffic simulation
⚔️
Attack Traffic
Kali → Ubuntu
Scans · Exploits · Brute Force
Web Attacks on DVWA
📡
Agent → SIEM
Kali Wazuh Agent → Ubuntu
Attacker logs forwarded
to Wazuh Manager
🔔
Alert & Detect
Wazuh Dashboard
Real-time alerts · IOCs
SOC Incident Reports
VirtualBox 7.x Kali Linux 2024 Ubuntu 22.04 LTS Wazuh 4.x SIEM DVWA UFW Firewall Apache2 MySQL Nmap Metasploit SQLmap Hydra