Wazuh SIEM
Central Log Management
Central log aggregation and alert triage. Collects Sysmon events from Windows and auditd logs from Linux. Correlates across endpoints to detect lateral movement and persistence.
Log AggregationAlert TriageCorrelation
Suricata IDS/IPS
Network Intrusion Detection
Network intrusion detection monitoring all traffic between VMs. Signature and anomaly-based analysis with EVE JSON output for Wazuh.
SignatureAnomalyEVE JSON
Windows Target VM
Sysmon Monitored
Windows endpoint with Sysmon for process, network, and registry monitoring. Primary target for phishing simulation and malware detonation.
SysmonPhishingMalware
Linux Target VM
Auditd Monitored
Linux endpoint with auditd for syscall-level monitoring. Used for privilege escalation and container escape testing.
AuditdPriv EscContainer Escape
Offensive security platform for simulating real-world attacks. Tests detection with phishing, exploitation, and lateral movement.
ExploitationPhishingLateral Movement