- Final Report -

SOC Lab Summary

A Short Review of the Last 3 Phases


Introduction


In this final report, we will summarize the work done in the SOC Lab. Emma and I have been working on this lab for the past 3 phases, and we have learned a lot about some foundational skills for each of us. While I have gained experience in Information Technology, I have never set up a lab like this before. We ran into some issues in the beginning, but we revised and learned from the experience. Emma having no IT Experience showed no barrier to learning. She grasped the initial concepts and quickly learned to use the Virtual Environment. She learned the basics of troubleshooting and got her first step into Information Technology.


We've worked through multiple challenges and have gained valuable insights into the field of cybersecurity. Initially we faced challenges regarding the set-up of our Linux Server we used to host Wazuh, including misconfiguration and failed deployments. Emma was dismayed by the complexity of the terminal and the learning curve, but she pushed through to continue working on this despite life taking multiple shifts.


We learned how to work together, and teach ourselves skills we didn't fully have developed. While we were unable to complete the lab as planned, we appreciate you taking the time to watch our failures and successes.


Set-Up


Our initial set-up involved configuring the virtual environment and installing the necessary software for our SOC lab. This included setting up the Linux server, installing Wazuh, and configuring the network settings. Along side Installing the Windows Environment, manual set-up of the User Accounts, Group Policy Settings, and Additional Software Installations.


Emma was initially overwhelmed by the technical aspects of the lab, but she persisted and gradually became more confident in her abilities. She led the majority of the set-up tasks and Windows Configurations outside of the Active Directory. This included installing the Operating Systems, and configuring the Group Policies. She domain joined the WorkStations after some troubleshooting efforts alongside myself.


I focused mostly on the Linux Server configuration and Wazuh-Manager Installation, due to taking multiple attempts to domain join the Ubuntu Server due to failed attempts and having to reset and reconfigure through the installation process. While I did assist with account creation, my work was primarily focused on the planning of this project and the initial attempt to get us started.


SIEM Set-Up


Once we had Wazuh up and running Emma continued to lead the work being done, while I attempted to guide her through the process and documentation for Wazuh, shortly after starting we had decided it would be better to attempt to use ChatGPT while I had access to the premium tier free trial. This led to the creation of our XML Templates, and Emma's contributions to the dashboards and configuration. After noticing Sysmon was logging incorrectly, we had to go back and revise our approach to the Wazuh Agent configurations.


Emma persisted through the challenges and made significant contributions to the project. Her ability to understand and build the dashboards were significantly improved through the use of ChatGPT. While we recognize now, after some further educational development, we have a few misconfigurations and some foundational errors due to the learning curve and limited time frame.


Overall, Emma managed to configure the dashboards herself, and get the logs appearing correctly within the Threat Hunter dashboard. Allowing us to review our progress and identify areas for improvement. We worked together to use ChatGPT to build rules, due to our VM's becoming more and more frustrating to work with. Due to our limited resources we could only have two VM's running at a time, before the system performance degraded.


Red Team Attempts


Our initial attempt to conduct the exercises were met with multiple perspective imbalances, while knowing the first steps required to attempt these exercises. I recognized the concern for the implications of a full attempt inside of a lab environment without proper safeguards and teachings. So the initial decision to lower the barrier for entry was made. Despite experience with scripting and a vast potential available, we chose to focus on the learning experience.


Emma was able to work through the first report before encountering difficulties due to a wrist injury that was limiting her ability to use her hand. The second report was guided by her, with me entering the logs we found on the SIEM. Looking back not rushing all of this would have provided a better outcome. Despite this being the first attempt at this project, Emma found an interest in Cyber Security and Digital Forensics from it.


We were unable to complete the third report due to the limitations mentioned in the last day of phase III, with that the logging was incomplete. The SIEM only provided minimal information for analysis of a network scan, and without the Firewall configuration working properly to report logged connections. We could not provide an accurate report of an attempt inside of the simulation.


Lessons Learned


Matthew: My skill-set while I believe are developed enough to set this up, lack in the correct area for teaching others. I am also unable to balance the workload effectively combined with standard day to day responsibilities, including Work, School Courses, and Personal Challenges. With that I take responsibility for the shortcomings and commit to improving in these areas with future projects. We're already seeing improvements in our approach and understanding of each other. And seek to find projects that are a good fit for our skills and interests.


Emma: It was a very difficult first project, as I do not know what I'm doing yet. But I'm working on improving my skills and knowledge in this area. I started to work through TryHackMe exercises, and learning paths. I believe this is something I understand better than I thought I would. While I still have a lot to learn, I am excited to continue learning.


Foot Note


We appreciate your time reading through our flops and failures, we hope you found some success stories inside. As a team we will continue to work on improving our skills and knowledge in this area.


Thank you for visiting.