Prepared and followed the GNS3 lab environment with Caldera, Windows/Linux targets, and domain-controller context.
Caldera + ELK Security Analysis Lab
Security audit lab using MITRE Caldera, Sandcat agents, GNS3 VMs, ELK/SIEM views, Wireshark captures, session logs, and MITRE-style evidence analysis.
Key highlights
- Focused on evidence correlation rather than only launching attack simulations.
- Worked with Caldera agents, target machines, domain-controller context, packet captures, ELK views, and session logs.
- Turned a lab exercise into a more professional incident-analysis case study with timeline and proof structure.
What I handled
Observed Sandcat agent deployment and attack-simulation behavior through Caldera operations.
Collected and compared network captures, ELK/SIEM observations, and session-log spreadsheets.
Separated evidence from instructions so the portfolio page stays focused on what was observed and documented.
Results & evidence
Correlation architecture
Timeline
Start the lab and agents
Use the GNS3 environment, Caldera console, and Sandcat agents to prepare attack-emulation visibility.
Observe and collect
Capture network traffic, check ELK/SIEM views, and record Caldera operation details during the scenario.
Correlate and report
Align timestamps, compare sources, label observations, and produce reusable investigation notes.
Overview
This project is a blue-team security analysis lab based on MITRE Caldera, ELK/SIEM observations, GNS3 virtual machines, and Wireshark packet captures.
The goal was not just to run a simulated attack. The useful part was to observe where the activity appears, compare several evidence sources, and document the result in a way that can support incident analysis.
Context
The uploaded material includes R5.Cyber.10 lab resources around:
- MITRE Caldera discovery
- Sandcat agent deployment
- lateral-movement observation
- SIEM and labelling work
- ELK views
- Wireshark captures
- monitoring and session spreadsheets
The lab context includes a Caldera audit VM, Windows target machines, a Linux user machine, and a Windows Server domain-controller environment.
What I worked on
The portfolio version of the project focuses on the useful professional skills:
- following Caldera operations and agent behavior
- collecting PCAP and log evidence
- comparing ELK observations with packet captures
- aligning activity by timestamps
- separating repeated sessions and background traffic
- turning observations into structured reporting material
Architecture / approach
The workflow is evidence-driven:
- prepare the lab machines
- deploy or observe Caldera agents
- run or follow an operation
- capture network traffic
- inspect ELK/SIEM logs
- compare the different traces
- label and explain what was visible
This is closer to real blue-team work than a simple “tool demonstration”.
Proof available
The project archive contains useful evidence sources:
- TP 1 and TP 2 lab documents
- Caldera/SIEM session spreadsheets
- monitoring logs
- scenario instructions and analysis material
The portfolio should not publish raw credentials or full lab statements. The useful public proof would be cleaned screenshots, a MITRE table, a short timeline, and sanitized IoC examples.
Results
This project demonstrates:
- event correlation mindset
- security-lab discipline
- comfort with PCAP and SIEM views
- ability to compare attack traces and normal/background traffic
- structured reporting under academic constraints
Limits and improvements
The current uploaded archive contains more lab resources than final polished evidence. A future pass should add only cleaned proof:
- one Caldera operation screenshot
- one ELK query/result screenshot
- one filtered Wireshark capture
- one MITRE ATT&CK mapping table
- one IoC/recommendation table
What this project demonstrates
This project supports my cybersecurity positioning because it shows the defensive side: observe, correlate, label, explain, and recommend.