Skip to content
All projects

Cybersecurity / Infrastructure

Elastic Security Home Lab

A self-hosted Elastic Security environment for hands-on research

Active Home LabNot publicly launched

Overview

A self-hosted Elastic Security lab built for hands-on SOC testing, detection engineering and security research.

The Problem

Understanding detection engineering and SOC tooling deeply requires more than reading documentation, it requires ingesting real telemetry and building/testing detections hands-on.

The Approach

A self-hosted lab environment running the Elastic Stack with real endpoint telemetry, used to experiment with detections, log ingestion and endpoint monitoring.

Where It Stands

Actively maintained as an ongoing home lab, used regularly for hands-on detection engineering, telemetry ingestion and SOC tooling practice rather than aimed at any external launch.

Architecture

  • Elasticsearch + Kibana
  • Elastic Agent & Fleet for endpoint management
  • Windows and Linux telemetry ingestion
  • Sysmon for extended Windows telemetry
  • Custom detection rules
  • Dockerized deployment

Key Features

Windows telemetry ingestion
Linux telemetry ingestion
Sysmon-based endpoint monitoring
Custom detection rules
Hands-on SOC investigation practice

Technologies

ElasticsearchKibanaElastic AgentFleetSysmonDocker

Status

Active Home Lab