Newsletter
Technical insights and practical cybersecurity resources
Deployed Splunk as a centralized SIEM across the full lab environment. Connected DC01 (Windows Server 2022) and three Windows 10 domain clients as data sources. Built detection rules for Kerberoasting (Event ID 4769) and Pass-the-Hash (Event ID 4624/4648), triggering real alerts from actual attack simulations. Developed a SOC dashboard visualizing security events across the domain in real time.
Technologies: Splunk, Splunk Universal Forwarder, Windows Event Logs, Active Directory, Kali Linux