Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🔍 SOC Multi-Source Log Correlation Lab

Hands-on SOC lab correlating Apache Access, SSH Auth, Firewall UFW, and Application logs to detect brute force + reconnaissance attacks


📌 Project Overview

This project demonstrates multi-source log correlation across 4 log types (Apache Access, SSH Authentication, UFW Firewall, Java Application) to build attack timelines and extract actionable IOCs for SOC triage.

Real SOC Scenario: Detect multi-vector attacks combining web reconnaissance → SSH brute force → automated firewall blocking (fail2ban).

Key Attackers Identified:

10.0.0.5 → Admin dashboard scan + SSH block (TA0007 Discovery)
10.0.0.6 → wp-login.php recon → SSH brute force ×12 → fail2ban BLOCK (T1110)

🎯 Learning Objectives

Master SOC skills including:

  • Multi-source log correlation (web + auth + firewall + app)
  • Attack timeline reconstruction across disparate formats
  • False positive filtering (app errors vs security incidents)
  • IOC extraction with MITRE ATT&CK mapping
  • SIEM correlation rule development

🛠️ Tools & Technologies

📊 SIEM:     Splunk, QRadar, ELK
📜 Logs:     Apache Access, SSHD Auth, UFW Firewall, Java App
🔍 Language: SPL (Splunk), KQL (Sentinel)
🛡️ Framework: MITRE ATT&CK (TA0007, T1110)

📂 Dataset Details

4 Raw Log Files (raw_logs/ folder):

Log File Source Key Fields Security Value
access.log Apache IP, timestamp, method, path, status Web recon, errors ppl-ai-file-upload.s3.amazonaws
auth.log SSHD timestamp, user, IP, success/fail Brute force detection ppl-ai-file-upload.s3.amazonaws
firewall.log UFW timestamp, IP, port, ALLOW/BLOCK Fail2ban auto-blocks ppl-ai-file-upload.s3.amazonaws
app_error.log Java timestamp, stack trace, endpoint False positive filtering ppl-ai-file-upload.s3.amazonaws

⚙️ Lab Setup & Data Ingestion

Step 1: Upload All 4 Logs

Splunk → Settings → Add Data → Upload
Indexes: soc_lab (recommended)
Source Types: 
  - access_log → apache:access_combined
  - auth_log → linux:syslog  
  - firewall_log → linux:ufw
  - app_error → java:app_error

Step 2: Verify Ingestion

index=soc_lab | stats count by source,sourcetype | sort -count

🔍 Analysis Tasks & SPL Queries

🔹 Task 1: Multi-Vector Attack Correlation

Detect IPs attacking web + SSH simultaneously

index=soc_lab (source_ip IN ("10.0.0.5","10.0.0.6")) 
| eval event_type=case(
    match(_raw,"wp-login|admin"),"WEB_RECON",
    match(_raw,"Failed password"),"SSH_BRUTE", 
    match(_raw,"UFW.*REJECT|BLOCK"),"FIREWALL_BLOCK"
)
| timechart span=1m count by event_type

🔹 Task 2: Attack Timeline (10:00-10:41)

index=soc_lab 
| where source_ip IN ("10.0.0.5","10.0.0.6")
| eval time_str=strftime(_time,"%H:%M:%S")
| table time_str,source_ip,event_type,status_code
| sort _time

🔹 Task 3: False Positive Filtering

index=soc_lab status_code=500 
| join type=inner timestamp [search index=soc_lab "NullPointerException"]
| table source_ip, status_code, error_message

📈 Attack Timeline Visualization

10:03:30 → 10.0.0.5 → /admin/dashboard [403] + SSH BLOCK (port 22)
10:08:00 → 10.0.0.6 → Recon: /wp-login.php → 404s (TA0007)
10:15:10 → 10.0.0.6 → SSH brute force: admin ×12 failures (T1110)  
10:15:27 → fail2ban → UFW REJECT port 22 → BLOCKED

📊 Extracted IOCs

Threat Actor IP MITRE ATT&CK TTPs Status
Attacker 1 10.0.0.5 TA0007 Admin recon + SSH BLOCKED
Attacker 2 10.0.0.6 T1110 Recon + Brute Force BLOCKED

🚨 SOC Action Items

✅ HIGH: Block 10.0.0.5, 10.0.0.6 (permanent)
✅ MED:  Monitor masscan scanner activity  
✅ LOW:  Dev ticket for /api/v1/user/123 (500 error)
✅ INFO: Normal user 192.168.1.4 workflow validated

✅ Key Findings

  • Detected 2x multi-vector attackers (web + SSH)
  • Correlated 4x log sources into attack timelines
  • Filtered false positives (app errors vs security)
  • Mapped MITRE ATT&CK techniques accurately
  • Built production SIEM rules for correlation

💼 Skills Demonstrated

  • Multi-source log correlation (Apache + Syslog + UFW + Java)
  • Attack timeline reconstruction (12-min attack chain)
  • IOC extraction + threat classification
  • False positive analysis + prioritization
  • SIEM query development (SPL, KQL)

Perfect for SOC L1, Threat Hunter, SIEM Engineer roles


🚀 Future Enhancements

  • Python log parser for automated correlation
  • Jupyter notebook with attack timeline visualization
  • GeoIP enrichment for attacker IPs
  • Automated alerting workflow
  • Sigma rule conversion

⭐ If you found this SOC lab useful, consider starring the repository!


Praharsh Kumar | Cybersecurity Analyst | Lucknow, UP
LinkedIn | CTIGA Certified

About

This project simulates a real SOC triage scenario where web attacks, SSH brute force, and firewall logs are correlated to identify multi-vector attacks and reduce false positives.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors