Blue Team / Splunk / Active Directory
Enterprise Active Directory + SIEM Home Lab
Built an on-premises virtual SOC lab using VMware Workstation, pfSense, Windows Server Active Directory, domain-joined clients, and Splunk to practice centralized logging and Blue-Team monitoring workflows.
- Designed a controlled network with pfSense as the gateway and Active Directory DNS as the authoritative internal DNS service.
- Forwarded and reviewed endpoint and server activity to support centralized log visibility and security investigation practice.
- Documented the lab architecture, screenshots, and analyst learning outcomes for portfolio evidence.