CASE FILE · 2026
SOC-Simulator
Local SOC lab with 30 triage and investigation scenarios covering around 2,950 synthetic events from 12 sources, with SPL/KQL queries and Sigma rules for each scenario.
EVIDENCE RECORD
What I built and what it proves.
- My role
- Designed and developed the lab: scenarios, SOC console, assessment API and synthetic datasets.
- Outcome
- Reference SPL/KQL queries and Sigma rules for each scenario, automated assessment, Challenge Mode and a timeline map; optional Elasticsearch/Kibana via Docker Compose.
- Validation
- Unit, API, component, reproducibility and IOC tests; schema, determinism, MITRE, query and Sigma validators for each scenario.
- Tools
- TypeScript · Elastic/Kibana · Node.js · Docker
Project stages
- 01
Signal
Practising triage and investigation requires realistic telemetry without running malware or interacting with external targets.
- 02
Context
30 progressive scenarios: fundamentals, multi-source correlation, multi-stage chains and ambiguous triage.
- 03
Implementation
Web-based SOC console following the analyst workflow: queue, severity, statuses, evidence, notes, questions and explained resolutions.
- 04
Telemetry
Around 2,950 reproducible events with benign noise from 12 sources: Windows, Sysmon, Linux, DNS, HTTP, authentication, network, Suricata, firewall, endpoint, email and cloud.
- 05
Security
All content is synthetic, and the server withholds the solution, timeline and IOCs until the investigation is submitted.
- 06
Validation
Unit, API, component, reproducibility and IOC tests.
- 07
Status
Completed and functional: all 30 scenarios, the console and automated assessment are implemented.
Sources
Documented from the repository's code and documentation and, where available, the published site.
- Status
- SOC practice lab