This project demonstrates hands-on experience with Security Incident Detection and Response using Wazuh SIEM in a home lab environment. The lab focuses on defensive monitoring, alert triage, investigation, impact assessment, and remediation planning across Windows 11 and Linux systems on the same internal network.
- SIEM: Wazuh
- Endpoints: Windows 11 VM, Linux VM
- Network: Internal / Home Wi-Fi
- Monitoring: Agent-based
- Monitored authentication activity and system events
- Assessed potential risks such as unauthorized access and privilege misuse
- Centralized log collection using SIEM
- Visibility into endpoint activity and integrity monitoring
- SIEM alerts provided visibility into authentication and system activity
- Reviewed logs and correlated events across endpoints
- Evaluated potential impact if abnormal activity went undetected
- Reviewed access controls and file integrity baselines
- Recommended stronger authentication and monitoring improvements
GCIH focuses on detecting incidents, investigating alerts, and performing containment and remediation.
This project demonstrates:
- Alert triage
- Incident timeline analysis
- Impact assessment
- Remediation decision-making
👉 This reflects GCIH capability without holding the certification.
Aniket Ambekar



