DIEGO URBANEJA
Blue Team

CASE FILE · 2026

SOC-Simulator

Local SOC lab with 30 triage and investigation scenarios covering around 2,950 synthetic events from 12 sources, with SPL/KQL queries and Sigma rules for each scenario.

Investigation in the console · IP search and attack chain

SOC-Simulator · demo

EVIDENCE RECORD

What I built and what it proves.

My role
Designed and developed the lab: scenarios, SOC console, assessment API and synthetic datasets.
Outcome
Reference SPL/KQL queries and Sigma rules for each scenario, automated assessment, Challenge Mode and a timeline map; optional Elasticsearch/Kibana via Docker Compose.
Validation
Unit, API, component, reproducibility and IOC tests; schema, determinism, MITRE, query and Sigma validators for each scenario.
Tools
TypeScript · Elastic/Kibana · Node.js · Docker

Project stages

  1. 01

    Signal

    Practising triage and investigation requires realistic telemetry without running malware or interacting with external targets.

  2. 02

    Context

    30 progressive scenarios: fundamentals, multi-source correlation, multi-stage chains and ambiguous triage.

  3. 03

    Implementation

    Web-based SOC console following the analyst workflow: queue, severity, statuses, evidence, notes, questions and explained resolutions.

  4. 04

    Telemetry

    Around 2,950 reproducible events with benign noise from 12 sources: Windows, Sysmon, Linux, DNS, HTTP, authentication, network, Suricata, firewall, endpoint, email and cloud.

  5. 05

    Security

    All content is synthetic, and the server withholds the solution, timeline and IOCs until the investigation is submitted.

  6. 06

    Validation

    Unit, API, component, reproducibility and IOC tests.

  7. 07

    Status

    Completed and functional: all 30 scenarios, the console and automated assessment are implemented.

View all projects →

Sources

Documented from the repository's code and documentation and, where available, the published site.

Status
SOC practice lab