Lab Setup, Environment, MISP & Splunk
Build the virtual environment, configure private networking, install the core platforms, and begin collecting Windows telemetry.
Read Part 1 →A hands-on project connecting SIEM detection, threat intelligence, automation, investigation, and MITRE ATT&CK into one end-to-end security workflow.
Security teams rely on many different platforms. A SIEM watches telemetry, threat-intelligence systems manage indicators, enrichment services add context, and case-management platforms help analysts investigate what happened.
I built this home lab to understand how those systems actually work together instead of studying each platform in isolation.
The project follows a controlled suspicious-file scenario through detection, enrichment, intelligence management, automated response, investigation, and MITRE ATT&CK mapping.
The lab connects endpoint telemetry, SIEM detection, automation, threat intelligence, investigation, and behavioural context into one connected workflow.
Activity begins on the monitored endpoint and is detected by Splunk. Automation moves structured context into the intelligence and investigation layers, while MITRE ATT&CK provides behavioural context where the available evidence supports the mapping.
Take the complete Threat-Intelligence-Driven Detection Lab with you as one structured PDF — all four parts, architecture, implementation steps, screenshots, validation, and technical notes together.
Follow the complete implementation in four focused parts, from infrastructure and telemetry to automated investigation.
Build the virtual environment, configure private networking, install the core platforms, and begin collecting Windows telemetry.
Read Part 1 →Connect the lab to external intelligence sources and safely validate threat-intelligence and file-hash enrichment.
Read Part 2 →Build the detection logic, normalize the alert data, and connect Splunk to the Python automation workflow.
Read Part 3 →Create investigation cases, attach observables, map supported behaviour to ATT&CK, and validate the complete pipeline.
Read Part 4 →The lab combines several security functions into one reproducible detection and investigation environment.
Splunk monitors endpoint activity and generates the initial detection.
Windows Security, System, and Firewall data provide the underlying evidence.
MISP, OTX, and VirusTotal provide indicator management and enrichment context.
Python and REST APIs move structured detection data between platforms.
TheHive turns detection context into structured cases and observables.
Observed behaviour is mapped to MITRE ATT&CK only where evidence supports it.
This is an educational cybersecurity lab built for defensive learning in an isolated home-lab environment.
Begin with the virtual environment, lab networking, MISP, Splunk, and Windows telemetry.
Start Part 1 →If this piece gave you something to think about, you can support my writing here ☕
We use cookies to improve your experience, analyze traffic, and support site functionality. You can accept all cookies, reject non-essential cookies, or manage your preferences. Read our Cookie Policy for more details.
We use cookies to improve your experience, analyze traffic, and personalize content. You can manage your preferences below. Blocking some cookies may affect how the site functions.
Essential cookies enable basic functions and are necessary for the proper function of the website.