r/netsecstudents • u/umid_guluzada • 16h ago
Built a Blue Team Infrastructure Lab (pfSense, Suricata, ELK Stack in VMware)
Hey everyone,
I wanted to share my latest hands-on Blue Team lab project focused on centralized network security, IDS/IPS, and SIEM monitoring.
Lab Architecture & Tech Stack:
pfSense: Acts as the firewall and router, handling network segmentation.
Suricata: Configured for intrusion detection and prevention (IDS/IPS).
ELK Stack (Ubuntu Server): Collects, analyzes, and visualizes security logs via Kibana.
Environment: Virtualized using VMware with a dedicated victim (Windows) and attacker (Kali Linux) setup.
The project has significantly helped me understand network traffic monitoring and log analysis. You can check out the full technical documentation, architecture diagrams, and setup details on my GitHub:
🔗 GitHub Repository: https://github.com/umidguluzada/CyberDefense-Lab
I would love to hear your feedback, suggestions, or ideas for the next steps!