ELK SIEM Honeypot
Security Operations · Public summary
Monitoring and investigating endpoint and network events in a controlled Windows/Linux security lab.
Technologies: ELK Stack · Google Cloud · Windows · Linux · Sysmon
Objective
Explore how endpoint and network telemetry can be collected and analysed for security monitoring.
Implementation
Built a controlled lab with Windows and Linux agents. Collected activity including authentication attempts and suspicious PowerShell execution, and explored log enrichment and dashboard views.
Lessons
Useful security detections rely on reliable telemetry, clear context and repeatable investigation steps. This is a personal lab, not a production deployment.