All projects
Cybersecurity / Infrastructure
Elastic Security Home Lab
A self-hosted Elastic Security environment for hands-on research
Active Home LabNot publicly launched
Overview
A self-hosted Elastic Security lab built for hands-on SOC testing, detection engineering and security research.
The Problem
Understanding detection engineering and SOC tooling deeply requires more than reading documentation, it requires ingesting real telemetry and building/testing detections hands-on.
The Approach
A self-hosted lab environment running the Elastic Stack with real endpoint telemetry, used to experiment with detections, log ingestion and endpoint monitoring.
Where It Stands
Actively maintained as an ongoing home lab, used regularly for hands-on detection engineering, telemetry ingestion and SOC tooling practice rather than aimed at any external launch.
Architecture
- Elasticsearch + Kibana
- Elastic Agent & Fleet for endpoint management
- Windows and Linux telemetry ingestion
- Sysmon for extended Windows telemetry
- Custom detection rules
- Dockerized deployment
Key Features
Windows telemetry ingestion
Linux telemetry ingestion
Sysmon-based endpoint monitoring
Custom detection rules
Hands-on SOC investigation practice
Technologies
ElasticsearchKibanaElastic AgentFleetSysmonDocker
Status
Active Home Lab