California State Polytechnic University, Pomona - Security Operations Center
Here lies the public directory and documentation of the Student run Security Operations Center at the California Polytechnic State University, Pomona.
Start Here!
SOC Lab Content
- Getting Started (Updated August 2025)
- Splunk Lab
- AD + Splunk Lab
- Splunk CTF Lab
- Overview
- Lab Structure
- Option 1 - Simulated Attack Environment with Virtual Machines
- Easy Challenges
- Medium Challenges
- Hard Challenges
- Option 2 - Importing a Pre-Existing Dataset (Cisco Secure Firewall Threat Defense Intrusion Events)
- Basic Exploration β Easy
- Counting & Classifying Intrusions β Medium
- Network Source / Destination β Medium
- Suspicious Activity Detection β Hard
- Conclusion
- Author & Credits
SOC Write-Up
- Implementation of Missile Map
- The First SOC-Syslog Incident
- The Fix of SOC-Syslog
- Overview
- Initial Problem: Disk Space Exhaustion
- Phase 1: Emergency Response
- Phase 2: Permanent Storage Solution
- Phase 3: Reconfiguring Splunk Forwarder
- Phase 4: Fixing Log Parsing on Splunk
- Phase 5: Building a Better Solution
- Phase 6: Transitioning to Proxmox
- Phase 7: Expanding Monitoring to Other VMs
- Final Result
- How the SOC receives alerts?