This repository contains cybersecurity attack simulations and incident analysis reports created as part of my SOC (Security Operations Center) learning and research.
The goal of this repository is to simulate real-world cyber attacks and document how they are detected, investigated, and mitigated using SOC monitoring techniques.
- Simulate common cyber attacks in a controlled lab environment
- Analyze system and network logs
- Develop detection rules for suspicious activity
- Document investigation methodology used in SOC environments
The simulations were performed using a virtual security lab.
Tools used:
- Kali Linux (Attacker machine)
- Linux / Windows Server (Target systems)
- Wazuh SIEM
- PostgreSQL
- Python
This repository currently contains the following incident analysis reports:
Simulation of SSH brute force login attempts and detection using log correlation.
Detection of network scanning activity using log analysis.
Analysis of abnormal authentication activity detected through security logs.
Each report includes:
- Attack simulation details
- Logs generated during the attack
- Detection methods
- Indicators of compromise
- Mitigation strategies
soc-attack-simulations
│
├── README.md
└── attack-reports
├── brute-force-detection.md
├── port-scan-detection.md
└── suspicious-login-analysis.md
- Security event monitoring
- Log analysis
- Threat detection
- Incident investigation
- Detection rule development
My cybersecurity portfolio:
https://yoonas18.github.io/portfolio
Yoonus KY Cybersecurity Researcher | SOC Analyst
GitHub: https://github.com/Yoonas18 LinkedIn: https://linkedin.com/in/yoonusky Email: Yoonasy703@gmail.com