Hands-on SOC lab correlating Apache Access, SSH Auth, Firewall UFW, and Application logs to detect brute force + reconnaissance attacks
This project demonstrates multi-source log correlation across 4 log types (Apache Access, SSH Authentication, UFW Firewall, Java Application) to build attack timelines and extract actionable IOCs for SOC triage.
Real SOC Scenario: Detect multi-vector attacks combining web reconnaissance → SSH brute force → automated firewall blocking (fail2ban).
Key Attackers Identified:
10.0.0.5 → Admin dashboard scan + SSH block (TA0007 Discovery)
10.0.0.6 → wp-login.php recon → SSH brute force ×12 → fail2ban BLOCK (T1110)
Master SOC skills including:
- Multi-source log correlation (web + auth + firewall + app)
- Attack timeline reconstruction across disparate formats
- False positive filtering (app errors vs security incidents)
- IOC extraction with MITRE ATT&CK mapping
- SIEM correlation rule development
📊 SIEM: Splunk, QRadar, ELK
📜 Logs: Apache Access, SSHD Auth, UFW Firewall, Java App
🔍 Language: SPL (Splunk), KQL (Sentinel)
🛡️ Framework: MITRE ATT&CK (TA0007, T1110)
4 Raw Log Files (raw_logs/ folder):
| Log File | Source | Key Fields | Security Value |
|---|---|---|---|
access.log |
Apache | IP, timestamp, method, path, status | Web recon, errors ppl-ai-file-upload.s3.amazonaws |
auth.log |
SSHD | timestamp, user, IP, success/fail | Brute force detection ppl-ai-file-upload.s3.amazonaws |
firewall.log |
UFW | timestamp, IP, port, ALLOW/BLOCK | Fail2ban auto-blocks ppl-ai-file-upload.s3.amazonaws |
app_error.log |
Java | timestamp, stack trace, endpoint | False positive filtering ppl-ai-file-upload.s3.amazonaws |
Splunk → Settings → Add Data → Upload
Indexes: soc_lab (recommended)
Source Types:
- access_log → apache:access_combined
- auth_log → linux:syslog
- firewall_log → linux:ufw
- app_error → java:app_error
index=soc_lab | stats count by source,sourcetype | sort -count
Detect IPs attacking web + SSH simultaneously
index=soc_lab (source_ip IN ("10.0.0.5","10.0.0.6"))
| eval event_type=case(
match(_raw,"wp-login|admin"),"WEB_RECON",
match(_raw,"Failed password"),"SSH_BRUTE",
match(_raw,"UFW.*REJECT|BLOCK"),"FIREWALL_BLOCK"
)
| timechart span=1m count by event_type
index=soc_lab
| where source_ip IN ("10.0.0.5","10.0.0.6")
| eval time_str=strftime(_time,"%H:%M:%S")
| table time_str,source_ip,event_type,status_code
| sort _time
index=soc_lab status_code=500
| join type=inner timestamp [search index=soc_lab "NullPointerException"]
| table source_ip, status_code, error_message
10:03:30 → 10.0.0.5 → /admin/dashboard [403] + SSH BLOCK (port 22)
10:08:00 → 10.0.0.6 → Recon: /wp-login.php → 404s (TA0007)
10:15:10 → 10.0.0.6 → SSH brute force: admin ×12 failures (T1110)
10:15:27 → fail2ban → UFW REJECT port 22 → BLOCKED
| Threat Actor | IP | MITRE ATT&CK | TTPs | Status |
|---|---|---|---|---|
| Attacker 1 | 10.0.0.5 | TA0007 | Admin recon + SSH | BLOCKED |
| Attacker 2 | 10.0.0.6 | T1110 | Recon + Brute Force | BLOCKED |
✅ HIGH: Block 10.0.0.5, 10.0.0.6 (permanent)
✅ MED: Monitor masscan scanner activity
✅ LOW: Dev ticket for /api/v1/user/123 (500 error)
✅ INFO: Normal user 192.168.1.4 workflow validated
- Detected 2x multi-vector attackers (web + SSH)
- Correlated 4x log sources into attack timelines
- Filtered false positives (app errors vs security)
- Mapped MITRE ATT&CK techniques accurately
- Built production SIEM rules for correlation
- Multi-source log correlation (Apache + Syslog + UFW + Java)
- Attack timeline reconstruction (12-min attack chain)
- IOC extraction + threat classification
- False positive analysis + prioritization
- SIEM query development (SPL, KQL)
Perfect for SOC L1, Threat Hunter, SIEM Engineer roles
- Python log parser for automated correlation
- Jupyter notebook with attack timeline visualization
- GeoIP enrichment for attacker IPs
- Automated alerting workflow
- Sigma rule conversion
⭐ If you found this SOC lab useful, consider starring the repository!
Praharsh Kumar | Cybersecurity Analyst | Lucknow, UP
LinkedIn | CTIGA Certified