Home Detection Lab
Home-based detection environment using PfSense, Splunk, Kali Linux, Ubuntu, Windows Server, and Windows endpoints to monitor and investigate simulated attacks.
/ the problem
Detection skill without a controllable lab is theoretical. A home SOC needed segmented networks, log collection, and a place to practice MITRE-mapped investigations safely.
/ approach
TrustCode built a home detection lab for monitoring, analysis, and MITRE-mapped incident documentation.
/ what we built
- PfSense firewall with inbound/outbound traffic control
- Splunk for real-time log monitoring and search
- Kali Linux for offensive simulation alongside Ubuntu Desktop
- Windows Server 2019 and Windows 10 endpoints for realistic telemetry
- Incident documentation and mitigation notes mapped to MITRE ATT&CK
/ the outcome
A sanitised, documented detection lab that demonstrates monitoring, analysis, and incident write-ups without exposing real credentials or private infrastructure details.
/ additional investigations
Forgando in Valdoria
Documented investigation exercise (details kept sanitised)
Titan Shield
Documented investigation exercise (details kept sanitised)
Azure Crest
Documented investigation exercise (details kept sanitised)
/ next case study
Jojo's Hospital, KQL Threat Investigation
