1. What is this lab for?

This lab helps you understand how an organization responds to a cyberattack, step by step.
It simulates a real-world situation where you need to:
- detect suspicious activity
- analyze what is happening
- identify the root cause
- take action quickly to reduce impact

In short: go from “something is wrong” to “the issue is under control”.

---

2. Lab Objectives

By the end of this lab, anyone should be able to:
- Understand how attacks are detected
- Read and interpret logs
- Identify abnormal behavior
- Know what actions to take during an incident
- Set up basic monitoring
- Structure an effective response

---

3. Tools Used (Real-world environment)

Main Platform (SIEM)
Splunk
Used to:
- centralize logs
- search for anomalies
- detect attacks

System Logs
Windows Event Logs
Show:
- logins
- errors
- suspicious activities

Advanced Monitoring
Sysmon
Tracks:
- process execution
- network connections
- suspicious behavior

Network Analysis
Wireshark
Analyzes network traffic (what is happening on the network)

---

4. Understanding tabs in Splunk

Search & Reporting
The main working area
Used to:
- search events
- filter activities
- detect anomalies

Example:
index=windows EventCode=4625
→ shows failed login attempts

Dashboard
Global view
Used to:
- visualize attacks
- monitor trends
- track activity in real time

Alerts
Automated detection
Used to:
- get notified when suspicious behavior occurs
- automate monitoring

Data Inputs
Data sources
Used to:
- ingest logs
- connect systems

Settings
Configuration
Used to:
- manage users
- configure data
- adjust system settings

---

5. Setup (Step-by-step)

Step 1: Install Splunk
1. Download the software
2. Install it normally
3. Open in browser:
http://localhost:8000
4. Create admin account

Step 2: Add Data
1. Go to Settings
2. Click Add Data
3. Choose:
- Windows logs
- or other sources
Goal: feed the system with data

Step 3: Install Sysmon (recommended)
1. Install Sysmon
2. Run:
sysmon -i config.xml
Enables deeper visibility

Step 4: Verify Data
In search:
index=main
If results appear → system is working

---

6. Incident Simulation

Step 5: Simulated scenario
Example:
Multiple failed login attempts (brute force attack)

Step 6: Detection
Search:
index=windows EventCode=4625
Shows:
- failed attempts
- targeted accounts
- possible sources

Step 7: Analysis
Key questions:
- Who is attacking? (IP address)
- Who is targeted? (user account)
- How many attempts?
- When did it happen?

Step 8: Timeline reconstruction
Organize events over time:
- start of activity
- repetition
- escalation

Step 9: Create alert
Trigger alert when:
multiple failures in a short time
Enables automatic detection

Step 10: Response actions
Possible actions:
- block suspicious IP
- secure user account
- isolate affected machine
- perform deeper investigation

Step 11: Reporting
A simple report should include:
- what happened
- source of the issue
- impacted systems
- actions taken
- prevention recommendations

---

7. Final Outcome

By the end of this lab:
- Incident is detected
- Situation is understood
- Actions are taken
- Monitoring is improved
- Report is created

---

Conclusion

This lab demonstrates how an organization:
- monitors systems
- detects threats
- investigates incidents
- responds effectively
- improves security posture

 

 

 

 



 

     

      

      
 

      

      

 


 

 

 

       

          

 

Copyright © All rights reserved.

 

     
* Cybersecurity Analyst
* SOC Analyst
* Security Operations Center
* Cloud Security
* DevSecOps
* Information Security
* Cybersecurity Engineer
* Threat Detection
* Incident Response
* SIEM Monitoring

---

# 🛡️ 2. Mots-clés SOC (très importants pour recrutement)

* SOC Analyst Tier 1
* SOC Analyst Tier 2
* Security Monitoring
* Log Analysis
* Security Alerts
* Threat Hunting
* Malware Analysis
* Phishing Detection
* Brute Force Detection
* Incident Investigation
* Security Events
* Blue Team

---

# ☁️ 3. Mots-clés Cloud Security

* Cloud Security Engineer
* AWS Security
* Azure Security
* Cloud Infrastructure Security
* Cloud Threat Detection
* Cloud Monitoring
* Identity and Access Management (IAM)
* Cloud Compliance
* Cloud Security Best Practices

---

# ⚙️ 4. Mots-clés DevSecOps

* DevSecOps Engineer
* Secure CI/CD Pipeline
* Security Automation
* Infrastructure as Code Security
* Docker Security
* Kubernetes Security
* Application Security
* Code Security
* SAST / DAST
* Continuous Security

---

# 🔬 5. Mots-clés techniques (très puissants SEO)

* Splunk
* ELK Stack (Elasticsearch, Logstash, Kibana)
* Microsoft Sentinel
* Wireshark
* Sysmon
* Linux Security
* Windows Security Logs
* Network Security
* Firewall Logs
* IDS / IPS

---

# 🚀 6. Mots-clés “portfolio / recrutement”

👉 Très important pour être trouvé par RH

* Cybersecurity Portfolio
* SOC Analyst Portfolio
* Cybersecurity Projects
* Cybersecurity Labs
* Security Use Cases
* Threat Detection Lab
* Cybersecurity Skills
* Entry Level Cybersecurity
* Junior Cybersecurity Analyst

---

# 📈 7. Mots-clés SEO longue traîne (ULTRA PUISSANT)

👉 Ceux-là font la différence 🔥

* Cybersecurity analyst portfolio website
* SOC analyst projects and labs
* How to detect cyber attacks using SIEM
* Cybersecurity incident response examples
* Cloud security best practices for beginners
* DevSecOps security pipeline example
* SIEM log analysis tutorial
* Threat detection use cases

---

# 🧠 STRATÉGIE SEO (très important)

## 📌 Où mettre ces mots-clés :

* Page d’accueil (titre + description)
* Page “About”
* Page “Labs”
* Titres H1 / H2 / H3
* Meta description
* URL des pages

---

# 🏆 EXEMPLE DE TITRE SEO (à utiliser)

👉
**Cybersecurity Analyst Portfolio | SOC, Cloud Security & DevSecOps Projects**

---

# 🏆 EXEMPLE META DESCRIPTION

👉
**Cybersecurity Analyst portfolio with hands-on labs in SOC monitoring, SIEM, Cloud Security and DevSecOps. Available for hiring.**

---
 

Manager DSI (secteur bancaire)

🎯 Mots-clés principau

# 🏦 🔥 1. Mots-clés Manager DSI (secteur bancaire)

## 🎯 Mots-clés principaux

* IT Manager
* IT Director
* Head of IT
* IT Governance
* Information Systems Management
* Digital Transformation
* IT Strategy
* Enterprise IT

---

## 🏦 Spécifique BANQUE (très puissant)

* Banking IT Systems
* Core Banking Systems
* Financial Information Systems
* Banking Cybersecurity
* Risk Management Banking
* IT Compliance Banking
* Data Protection Banking
* Financial Security

---

## ⚖️ Gouvernance & conformité

* IT Governance Framework
* COBIT
* ITIL
* Risk Assessment
* Business Continuity Plan (BCP)
* Disaster Recovery Plan (DRP)
* Regulatory Compliance

---

## 📊 Management & pilotage

* IT Project Management
* Team Leadership IT
* IT Operations Management
* KPI IT Performance
* IT Service Management (ITSM)
* Strategic IT Planning

---

# 🏥 🛡️ 2. Mots-clés RSSI (hôpital / santé)

## 🎯 Mots-clés principaux

* Chief Information Security Officer (CISO)
* Information Security Manager
* Cybersecurity Governance
* Security Risk Management
* Security Policies

---

## 🏥 Spécifique SANTÉ (très important)

* Healthcare Cybersecurity
* Hospital Information Systems (HIS)
* Patient Data Protection
* Medical Data Security
* Health IT Security
* Electronic Health Records (EHR) Security

---

## 🔐 Sécurité & conformité

* ISO 27001
* NIST Cybersecurity Framework
* GDPR Compliance
* Data Privacy
* Access Control
* Identity Management

---

## 🚨 Gestion des incidents

* Incident Response Management
* Security Operations Management
* Cyber Risk Assessment
* Vulnerability Management
* Threat Intelligence

---

# 🚀 🧠 3. Mots-clés hybrides (TRÈS PUISSANTS 🔥)

👉 Ceux-là font le lien entre ton profil actuel et ton évolution :

* Cybersecurity Leadership
* IT Security Strategy
* Enterprise Security Architecture
* Security Governance
* IT Risk Management
* Digital Security Transformation
* Cloud Security Governance