Caldera + ELK Security Analysis Lab

Security audit lab using MITRE Caldera, Sandcat agents, GNS3 VMs, ELK/SIEM views, Wireshark captures, session logs, and MITRE-style evidence analysis.

Date2026-03-27
CategoryAcademic
RoleLab execution, evidence collection, log/PCAP correlation, timeline analysis, and reporting
StackMITRE Caldera • Sandcat agents • Elastic Stack • GNS3 • Windows Server / AD • Windows 10 target • Ubuntu • Wireshark
CalderaELKSIEMWiresharkMITRE ATT&CKIncident analysis

Key highlights

  • Focused on evidence correlation rather than only launching attack simulations.
  • Worked with Caldera agents, target machines, domain-controller context, packet captures, ELK views, and session logs.
  • Turned a lab exercise into a more professional incident-analysis case study with timeline and proof structure.
ContextR5.Cyber.10 security audit lab
ScenarioCaldera adversary emulation with lateral-movement observation
Evidence sourcesCaldera operations, Sandcat agents, ELK logs, Wireshark PCAPs, and session spreadsheets
GoalCorrelate simulated attack activity and produce reusable blue-team evidence

What I handled

01

Prepared and followed the GNS3 lab environment with Caldera, Windows/Linux targets, and domain-controller context.

02

Observed Sandcat agent deployment and attack-simulation behavior through Caldera operations.

03

Collected and compared network captures, ELK/SIEM observations, and session-log spreadsheets.

04

Separated evidence from instructions so the portfolio page stays focused on what was observed and documented.

Results & evidence

Attack emulationCaldera + SandcatThe lab uses MITRE Caldera concepts such as agents, abilities, adversaries, and operations.
Target contextUSER workstation + domain controllerThe scenario includes Windows targets and a domain-controller environment.
Blue-team proofELK + PCAP + logsEvidence is collected from several views instead of relying on one console only.
DeliverablesTP reports + session spreadsheetsThe uploaded material includes structured lab documents and monitoring/session log files.

Correlation architecture

Diagram of the Caldera, ELK, and Wireshark lab showing attack orchestration, target hosts, packet capture, and SIEM correlation.
The architecture image shows how attack emulation, target machines, packet capture, and SIEM analysis connect.

Timeline

Step 1

Start the lab and agents

Use the GNS3 environment, Caldera console, and Sandcat agents to prepare attack-emulation visibility.

Step 2

Observe and collect

Capture network traffic, check ELK/SIEM views, and record Caldera operation details during the scenario.

Step 3

Correlate and report

Align timestamps, compare sources, label observations, and produce reusable investigation notes.

Overview

This project is a blue-team security analysis lab based on MITRE Caldera, ELK/SIEM observations, GNS3 virtual machines, and Wireshark packet captures.

The goal was not just to run a simulated attack. The useful part was to observe where the activity appears, compare several evidence sources, and document the result in a way that can support incident analysis.

Context

The uploaded material includes R5.Cyber.10 lab resources around:

  • MITRE Caldera discovery
  • Sandcat agent deployment
  • lateral-movement observation
  • SIEM and labelling work
  • ELK views
  • Wireshark captures
  • monitoring and session spreadsheets

The lab context includes a Caldera audit VM, Windows target machines, a Linux user machine, and a Windows Server domain-controller environment.

What I worked on

The portfolio version of the project focuses on the useful professional skills:

  • following Caldera operations and agent behavior
  • collecting PCAP and log evidence
  • comparing ELK observations with packet captures
  • aligning activity by timestamps
  • separating repeated sessions and background traffic
  • turning observations into structured reporting material

Architecture / approach

The workflow is evidence-driven:

  1. prepare the lab machines
  2. deploy or observe Caldera agents
  3. run or follow an operation
  4. capture network traffic
  5. inspect ELK/SIEM logs
  6. compare the different traces
  7. label and explain what was visible

This is closer to real blue-team work than a simple “tool demonstration”.

Proof available

The project archive contains useful evidence sources:

  • TP 1 and TP 2 lab documents
  • Caldera/SIEM session spreadsheets
  • monitoring logs
  • scenario instructions and analysis material

The portfolio should not publish raw credentials or full lab statements. The useful public proof would be cleaned screenshots, a MITRE table, a short timeline, and sanitized IoC examples.

Results

This project demonstrates:

  • event correlation mindset
  • security-lab discipline
  • comfort with PCAP and SIEM views
  • ability to compare attack traces and normal/background traffic
  • structured reporting under academic constraints

Limits and improvements

The current uploaded archive contains more lab resources than final polished evidence. A future pass should add only cleaned proof:

  • one Caldera operation screenshot
  • one ELK query/result screenshot
  • one filtered Wireshark capture
  • one MITRE ATT&CK mapping table
  • one IoC/recommendation table

What this project demonstrates

This project supports my cybersecurity positioning because it shows the defensive side: observe, correlate, label, explain, and recommend.

Crafted in France. © 2026 Kopethan ARUDSHELVAN (Kopy).