Cybersecurity / Detection engineering
Windows SOC Detection Lab
A Windows and Sysmon telemetry pipeline into Splunk, with seven detections covering encoded PowerShell, failed logons, persistence, and misleading email attachment extensions.
- Splunk SPL
- Sysmon
- PowerShell
Project notes
The lab is in progress. Gmail ingestion and scheduled alerts have been validated; continuous email polling has not been validated.