1. What is this lab for?
This lab teaches you how to:
- Monitor security logs
- Detect cyberattacks (e.g., brute force)
- Analyze events in a SIEM
- Create automated alerts
- Understand the role of a SOC analyst (L1)

In short:
You learn how to detect cyber threats in real time like a SOC analyst.

---

2. Learning objectives
By the end of this lab, you will be able to:
- Use Splunk effectively
- Ingest and manage logs (Windows/Linux)
- Search and investigate suspicious activity
- Detect brute force attacks
- Create security alerts
- Build SOC dashboards

---

3. Tools used

Main tool:
- Splunk (SIEM platform)

Log sources:
- Windows Event Logs
- Linux auth.log
- Apache / SSH logs

SOC concepts:
- SIEM (Security Information & Event Management)
- Log analysis
- Alerting
- Correlation rules

---

4. Splunk interface – key tabs
When you open Splunk, you’ll see:

1. Search & Reporting
The core of the SIEM
- Search logs
- Investigate events
- Detect attacks

2. Dashboards
Data visualization
- Attack trends
- Failed login graphs
- User activity

3. Alerts
Automated detection
- Brute force alerts
- Email/SOC notifications

4. Settings
System configuration
- Add data sources
- Manage indexing

5. Apps
Splunk extensions
- Security content
- Enterprise Security (ES)

---

5. Splunk installation (step by step)

Step 1: Download Splunk
- Go to the official website
- Download Splunk Enterprise

Step 2: Install
- Double-click installer
- Click: Next → Next → Install
- Create admin account:
- Username: admin
- Password: ********

Step 3: Launch Splunk
Open your browser:
http://localhost:8000

You will access the Splunk dashboard

---

6. Log ingestion (VERY IMPORTANT)

Step 1: Add Data
- Go to: Settings → Add Data

Step 2: Choose source
- Select “Upload files”
- Or “Monitor”

Step 3: Select logs
Examples:
- Linux auth.log
- Windows Security logs

Step 4: Indexing
- Create index: security

---

7. Detecting a brute force attack (real SOC case)

Scenario:
An attacker tries multiple SSH passwords

Step 1: Go to Search
Open: Search & Reporting

Step 2: SPL query
```
index=security sourcetype=linux_secure "Failed password"
```

Step 3: Analysis
You will observe:
- Multiple failed logins
- Same IP repeating
- Same user targeted

Brute force indicator:
Too many failed logins in a short time

Step 4: Identify suspicious IP
```
index=security "Failed password"
| stats count by src_ip
| sort -count
```

Result:
- IP with high number of attempts = suspicious

---

8. Creating a SOC alert

Step 1: Save as Alert
In Search:
- Click “Save As → Alert”

Step 2: Configure
- Name: Brute Force SSH Detection
- Condition:
- Number of results > 10
- Time range: 5 minutes

Step 3: Actions
- Send email
- Trigger script
- Create SOC ticket

---

9. Creating a SOC dashboard

Step 1: Dashboards
- Go to “Dashboards”
- Click “Create New Dashboard”

Step 2: Add panels

Panel 1:
- Failed logins over time

Panel 2:
- Top attacking IPs

Panel 3:
- Targeted users

---

10. Final lab outcome
At the end of the lab, you will have:
- Detected a brute force attack
- Identified a malicious IP
- Configured a SOC alert
- Built a monitoring dashboard
- Understood SOC L1 workflow

---

11. Prevention (SOC best practices)
- Block suspicious IPs (firewall)
- Enable MFA
- Limit login attempts
- Continuous SIEM monitoring
- Use tools like Fail2ban (Linux)

---

Conclusion
This Splunk lab simulates a real SOC environment:
- Log collection
- Threat detection
- Investigation
- Response
- Automation


 

 

 

 



 

     

      

      
 

      

      

 


 

 

 

       

          

 

Copyright © All rights reserved.

 

     
* Cybersecurity Analyst
* SOC Analyst
* Security Operations Center
* Cloud Security
* DevSecOps
* Information Security
* Cybersecurity Engineer
* Threat Detection
* Incident Response
* SIEM Monitoring

---

# 🛡️ 2. Mots-clés SOC (très importants pour recrutement)

* SOC Analyst Tier 1
* SOC Analyst Tier 2
* Security Monitoring
* Log Analysis
* Security Alerts
* Threat Hunting
* Malware Analysis
* Phishing Detection
* Brute Force Detection
* Incident Investigation
* Security Events
* Blue Team

---

# ☁️ 3. Mots-clés Cloud Security

* Cloud Security Engineer
* AWS Security
* Azure Security
* Cloud Infrastructure Security
* Cloud Threat Detection
* Cloud Monitoring
* Identity and Access Management (IAM)
* Cloud Compliance
* Cloud Security Best Practices

---

# ⚙️ 4. Mots-clés DevSecOps

* DevSecOps Engineer
* Secure CI/CD Pipeline
* Security Automation
* Infrastructure as Code Security
* Docker Security
* Kubernetes Security
* Application Security
* Code Security
* SAST / DAST
* Continuous Security

---

# 🔬 5. Mots-clés techniques (très puissants SEO)

* Splunk
* ELK Stack (Elasticsearch, Logstash, Kibana)
* Microsoft Sentinel
* Wireshark
* Sysmon
* Linux Security
* Windows Security Logs
* Network Security
* Firewall Logs
* IDS / IPS

---

# 🚀 6. Mots-clés “portfolio / recrutement”

👉 Très important pour être trouvé par RH

* Cybersecurity Portfolio
* SOC Analyst Portfolio
* Cybersecurity Projects
* Cybersecurity Labs
* Security Use Cases
* Threat Detection Lab
* Cybersecurity Skills
* Entry Level Cybersecurity
* Junior Cybersecurity Analyst

---

# 📈 7. Mots-clés SEO longue traîne (ULTRA PUISSANT)

👉 Ceux-là font la différence 🔥

* Cybersecurity analyst portfolio website
* SOC analyst projects and labs
* How to detect cyber attacks using SIEM
* Cybersecurity incident response examples
* Cloud security best practices for beginners
* DevSecOps security pipeline example
* SIEM log analysis tutorial
* Threat detection use cases

---

# 🧠 STRATÉGIE SEO (très important)

## 📌 Où mettre ces mots-clés :

* Page d’accueil (titre + description)
* Page “About”
* Page “Labs”
* Titres H1 / H2 / H3
* Meta description
* URL des pages

---

# 🏆 EXEMPLE DE TITRE SEO (à utiliser)

👉
**Cybersecurity Analyst Portfolio | SOC, Cloud Security & DevSecOps Projects**

---

# 🏆 EXEMPLE META DESCRIPTION

👉
**Cybersecurity Analyst portfolio with hands-on labs in SOC monitoring, SIEM, Cloud Security and DevSecOps. Available for hiring.**

---
 

Manager DSI (secteur bancaire)

🎯 Mots-clés principau

# 🏦 🔥 1. Mots-clés Manager DSI (secteur bancaire)

## 🎯 Mots-clés principaux

* IT Manager
* IT Director
* Head of IT
* IT Governance
* Information Systems Management
* Digital Transformation
* IT Strategy
* Enterprise IT

---

## 🏦 Spécifique BANQUE (très puissant)

* Banking IT Systems
* Core Banking Systems
* Financial Information Systems
* Banking Cybersecurity
* Risk Management Banking
* IT Compliance Banking
* Data Protection Banking
* Financial Security

---

## ⚖️ Gouvernance & conformité

* IT Governance Framework
* COBIT
* ITIL
* Risk Assessment
* Business Continuity Plan (BCP)
* Disaster Recovery Plan (DRP)
* Regulatory Compliance

---

## 📊 Management & pilotage

* IT Project Management
* Team Leadership IT
* IT Operations Management
* KPI IT Performance
* IT Service Management (ITSM)
* Strategic IT Planning

---

# 🏥 🛡️ 2. Mots-clés RSSI (hôpital / santé)

## 🎯 Mots-clés principaux

* Chief Information Security Officer (CISO)
* Information Security Manager
* Cybersecurity Governance
* Security Risk Management
* Security Policies

---

## 🏥 Spécifique SANTÉ (très important)

* Healthcare Cybersecurity
* Hospital Information Systems (HIS)
* Patient Data Protection
* Medical Data Security
* Health IT Security
* Electronic Health Records (EHR) Security

---

## 🔐 Sécurité & conformité

* ISO 27001
* NIST Cybersecurity Framework
* GDPR Compliance
* Data Privacy
* Access Control
* Identity Management

---

## 🚨 Gestion des incidents

* Incident Response Management
* Security Operations Management
* Cyber Risk Assessment
* Vulnerability Management
* Threat Intelligence

---

# 🚀 🧠 3. Mots-clés hybrides (TRÈS PUISSANTS 🔥)

👉 Ceux-là font le lien entre ton profil actuel et ton évolution :

* Cybersecurity Leadership
* IT Security Strategy
* Enterprise Security Architecture
* Security Governance
* IT Risk Management
* Digital Security Transformation
* Cloud Security Governance