skip to content
← cd ~/engagements
Infrastructure · 2025–2026

Multi-Endpoint Monitoring Lab

Multi-host virtualised lab (Windows 10, Kali Linux) with agent-based log forwarding from several endpoints into centralised dashboards — network configuration, host connectivity and full-fleet visibility, built from scratch and documented.

  • Wazuh agents
  • Splunk
  • Virtualised lab
  • Centralised logging

objective

Get full-fleet visibility across a mixed Windows and Linux estate, then test whether that visibility is real.

environment

  • Windows 10
  • Kali Linux
  • Virtualised lab
  • Wazuh agents
  • Splunk

approach

  1. 01Deployed and configured endpoint agents across several hosts with agent-based log forwarding into centralised dashboards.
  2. 02Covered network configuration and host connectivity as part of the build, not as an afterthought.
  3. 03Pushed simulated attack traffic through the estate to see what the dashboards actually surfaced.

outcome

  • Centralised network and system telemetry across the fleet.
  • Detection gaps identified from the simulated traffic and closed.

how it works

detection pipeline — what a single event passes through
endpointwindows · linuxagentsysmon · syslogmanagerdecodersrulematch · levelalerttriage queueresponsecontain · reporta gap at any stage means the alert never arrives — which stage failed is the whole question

highlights

  • $Endpoint agents deployed and configured across hosts
  • $Simulated attack traffic analysed to find detection gaps
  • $Dashboards built for network and system telemetry

scope

Every technique referenced here was executed inside authorised environments — my own virtualised lab hosts, DVWA, and systems I was engaged to assess. Attack simulation is always paired with the detection or hardening that answers it: that pairing is the whole point of the work, not a disclaimer on it.