A connected set of local security labs covering controlled attack telemetry, detection and triage, packet evidence, secure application controls, and cloud-monitoring architecture.
Independent buildReviewed July 2026
A synthetic SOC dashboard is one view inside the collection; its metrics and alerts come from a fixed local dataset.
For
Technical teams evaluating how David moves from system behavior to evidence, detection, investigation, control design, and an honest statement of limits.
Role
Lab architecture, fixtures, detection content, reporting, interface work, and validation
Evidence
Curated public case study with reviewed local artifacts
The problem
Why this needed to exist.
A list of small security repositories can look fragmented. The stronger story is the shared operating loop: constrain the environment, generate inspectable evidence, analyze it, make a decision, and retest the control.
Defining decision
Group the labs by the security decision they support instead of presenting every repository as an independent product.
Approach
How the system was shaped.
Kept scenarios inside local or repository-created boundaries and used synthetic, deterministic fixtures wherever practical.
Linked alerts and conclusions back to rules, events, packet numbers, or visible application controls.
Documented what each lab demonstrates separately from what would still be required in a production environment.
Tradeoffs
What the design chooses—and gives up.
Deterministic local environments improve repeatability and safety but do not model production scale or operational noise.
Transparent teaching implementations favor legibility over commercial-platform breadth.
Evidence
What can be inspected.
The cyber range connects a bounded gateway-to-Elastic telemetry path with detections, investigation evidence, hardening, and a comparable retest.
The SOC dashboard uses a fixed synthetic dataset, seven portable rules, and evidence-level alert detail.
Packet, web-security, and cloud labs publish portable reports or visible controls without requiring a paid deployment.
Limitations
What this does not claim.
These are portfolio labs, not production SIEM, incident-response, WAF, or cloud deployments.
The collection does not claim public targets, customer data, or enterprise operating scale.
Lessons
What carries into the next system.
Security evidence becomes more useful when the target boundary, rule logic, supporting event, and retest can be reviewed together.
Inside the collection
Five labs, one evidence loop.
Each lab stays narrow enough to inspect while contributing a different view of detection, investigation, control, or observability.
01
Cyber Range Red/Blue Lab
Controlled web telemetry, detections, investigation, hardening, and retest
Bounded local target with deterministic events and rule-linked alerts
02
SOC Alert Dashboard
Detection definitions, alert queue, evidence detail, and incident summary
Seven rules evaluated against a fixed synthetic dataset
03
Network Packet Analysis
DNS, ARP, HTTP, connection, ICMP, and UDP observations
Portable reports with source frame references
04
Web Security Fundamentals
Authentication, authorization, CSRF, data scope, and browser controls
Visible control status plus tests and HTTP probes
05
Azure Security Monitoring
Local-to-cloud service, logging, monitoring, and infrastructure model
Local load distribution with optional, non-applied Azure infrastructure code
Selected artifacts
Additional views of the working system.
The investigation queue keeps each synthetic alert tied to its rule, entity, timestamp, status, and supporting detail.The portable packet report keeps observations tied to supporting frame numbers in a synthetic capture.The secure-development lab makes authorization, CSRF, password, cookie, header, encoding, and input controls visible.
Open to the right conversation
Want to connect this technical example to the professional work?
Use the case study as a supporting example, then start with the customer, commercial, or operating decision that matters for the role.