π₯ 3,000+ Realistic Security Events | π― 30+ MITRE ATT&CK Techniques | π₯οΈ 4 SIEM Output Formats
Praharsh Kumar SOC Analyst | Detection Engineer | Multi-SIEM Lab Builder
This is my personal SIEM log generator, built for my Multi-VM SOC Lab. I use this to practice threat hunting, build detection rules, and test my Splunk, Wazuh, ELK, and Microsoft Sentinel setups.
Unlike generic log generators, this one is built around a real lab environment β the IPs, hostnames, attack techniques, and tool names all match what I actually run in my lab.
Kali Linux (Attacker) β 192.168.66.104
Windows 10 VM (Target) β 192.168.66.105
Splunk Enterprise VM β 192.168.56.101
Wazuh Manager VM β 192.168.66.102
ELK Stack VM β 192.168.66.103
| Feature | Generic Generators | This Project |
|---|---|---|
| Output formats | JSON + CSV only | JSON + CSV + Wazuh + Sentinel |
| Lab IPs | Generic/random | Your actual lab IPs |
| Attack tools | Not specified | Hydra, Mimikatz, Metasploit, Nmap |
| Sysmon events | Basic | Event IDs 1, 3, 7, 8, 11, 13 |
| Wazuh format | β | β Rule levels + Agent info |
| Sentinel format | β | β KQL-ready fields |
| MITRE coverage | ~15 techniques | 30+ techniques |
| Event count | 2,500 | 3,000+ |
| Category | Event Types | MITRE Techniques |
|---|---|---|
| π Authentication | Failed Login, Brute Force, RDP BF, SSH BF, Password Spray, Kerberoasting | T1110, T1558 |
| π» Sysmon | Process Create, Network Conn, Image Load, File Create, Registry Set | T1003, T1055, T1547 |
| π Execution | Reverse Shell, PowerShell, LOLBIN, WMI | T1059, T1218, T1047 |
| πΌ Privilege Esc | Token Impersonation, SeDebugPrivilege | T1068 |
| π Lateral Movement | RDP, PsExec, WMI Remote | T1021, T1570 |
| π€ C2 & Exfil | C2 Outbound, DNS Tunneling, Data Transfer | T1071, T1048 |
| π‘οΈ Endpoint | Mimikatz, Process Injection, Malware, Ransomware | T1003, T1055, T1486 |
| βοΈ Cloud | IAM Abuse, Impossible Travel | T1098, T1078.004 |
| π Network | Firewall Blocks, Port Scans (Nmap), IDS Alerts | T1046 |
| π§ Email | Phishing, Malicious Attachments | T1566 |
| π Wazuh | Rule-based alerts from Wazuh Manager | Various |
- Python 3.8+
- No external dependencies (standard library only)
# Clone
git clone https://github.com/praharsh-kumar/siem-log-generator.git
cd siem-log-generator
# Generate all logs
python generate_logs.py
# Convert formats
python convert_to_csv.pyoutput/
βββ praharsh_siem_logs_3000.json β Full JSON (all fields)
βββ praharsh_siem_logs_3000.csv β Splunk / ELK import
βββ praharsh_siem_logs_wazuh.json β Wazuh-format (rule levels + agents)
βββ praharsh_siem_logs_sentinel.json β Microsoft Sentinel KQL-ready
# Upload CSV via Splunk Web
Settings β Add Data β Upload β praharsh_siem_logs_3000.csv
# Or monitor file
splunk add monitor /path/to/praharsh_siem_logs_3000.csv -sourcetype csvBase SPL query:
source="praharsh_siem_logs_3000.csv" sourcetype="csv"
| head 20
# Copy to Wazuh manager
cp output/praharsh_siem_logs_wazuh.json /var/ossec/logs/alerts/Use the Sentinel KQL-ready JSON with Azure Log Analytics API:
import requests, json
with open("output/praharsh_siem_logs_sentinel.json") as f:
logs = json.load(f)
# POST to Log Analytics workspace
headers = {"Authorization": "Bearer YOUR_TOKEN", "Content-Type": "application/json"}
requests.post("https://api.loganalytics.io/v1/workspaces/YOUR_WS/query",
headers=headers, json={"logs": logs})KQL query example:
praharsh_siem_logs_CL
| where Severity == "Critical"
| where MitreTechnique startswith "T1003"
| summarize count() by Computer, EventType
| sort by count_ descinput {
file {
path => "/path/to/praharsh_siem_logs_3000.json"
codec => json
start_position => "beginning"
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
index => "praharsh-soc-lab-%{+yyyy.MM.dd}"
}
}A complete Splunk dashboard is included in docs/SPLUNK_DASHBOARD_GUIDE.md.
Panels included:
- Total Event Count
- Security Events Over Time (by severity)
- MITRE ATT&CK Technique Distribution
- User Risk Scores
- Failed Login Trends
- C2 Communication Hotspots
- Security Posture Score (Gauge)
- Recent Malware Detections Table
- Most Targeted Hosts
| Tactic | Techniques |
|---|---|
| Initial Access | T1566 (Phishing), T1078 (Valid Accounts) |
| Execution | T1059 (PowerShell/CMD), T1218 (LOLBIN), T1047 (WMI) |
| Persistence | T1053 (Sched Task), T1547 (Registry), T1543 (Service) |
| Privilege Escalation | T1068, T1055 (Process Injection) |
| Defense Evasion | T1070 (Log Clear), T1562 (Disable AV), T1218 (LOLBIN) |
| Credential Access | T1003 (Mimikatz/LSASS), T1110 (Brute Force), T1558 (Kerberoasting) |
| Discovery | T1046 (Nmap Port Scan) |
| Lateral Movement | T1021 (RDP), T1570 (PsExec) |
| C2 | T1071 (C2 Outbound), T1071.004 (DNS Tunnel) |
| Exfiltration | T1048 (Data Transfer) |
| Impact | T1486 (Ransomware) |
| Cloud | T1098 (IAM Abuse), T1078.004 (Impossible Travel) |
Edit the config section in generate_logs.py:
# Update with your actual VM IPs
internal_ips = [
"192.168.66.105", # Your Windows VM
"192.168.66.101", # Your Splunk VM
...
]
attacker_ip = "192.168.66.104" # Your Kali VM
# Add your own hostnames
hosts = ["WIN-PRAHARSH-01", "SPLUNK-VM-01", ...]siem-log-generator/
βββ π generate_logs.py # Main script β 3000+ events, 28 event types
βββ π convert_to_csv.py # JSON to CSV converter
βββ π output/
β βββ praharsh_siem_logs_3000.json
β βββ praharsh_siem_logs_3000.csv
β βββ praharsh_siem_logs_wazuh.json
β βββ praharsh_siem_logs_sentinel.json
βββ π README.md
βββ π USAGE.md
βββ π docs/
β βββ SPLUNK_DASHBOARD_GUIDE.md
β βββ ENTERPRISE_SOC_DASHBOARDS.md
βββ π requirements.txt
MIT License β free to use, share, and modify.
Built for my Multi-SIEM SOC Lab π‘οΈ | Splunk + Wazuh + ELK + Sentinel