Kubernetes SOC Field Lab

Build a hands-on SOC lab on Kubernetes using Wazuh.

A guided lab path for deploying Wazuh on Kubernetes, troubleshooting the platform, deploying Kubernetes and Windows host agents, generating safe security events, and using Wazuh from a SOC analyst perspective.

What this path is for

This lab series builds on Kubernetes Field Notes and uses Wazuh to create a practical SOC-style environment. The goal is to understand how Kubernetes operations, Wazuh deployment, agent enrollment, SIEM visibility, endpoint monitoring, alert triage, detection notes, incident workflow, and cleanup fit together.

Field note: This path is intended to be followed as a working lab. If something breaks, the troubleshooting is part of the training. The lab now includes both a Kubernetes DaemonSet agent and a Windows host agent so the reader can compare cluster telemetry with host telemetry.

Prerequisites from Kubernetes Field Notes

  • Setting Up a Local Kubernetes Lab
  • Namespaces
  • Persistent Storage
  • ServiceAccounts and RBAC
  • NetworkPolicies
  • Observability
  • Kubernetes Troubleshooting Playbook

Recommended path

Work through these lessons in order. The path starts with SOC concepts, moves into Wazuh-on-Kubernetes deployment and troubleshooting, then adds Kubernetes and Windows endpoint monitoring before moving into safe event generation, alert investigation, detection notes, and incident workflow.

SOC Foundations

1. What a SOC Lab Actually Is

Define SOC, SIEM, XDR, telemetry, alerts, triage, investigations, findings, and the purpose of a safe lab.

SOC Architecture

2. Kubernetes SOC Lab Architecture

Design the lab namespaces, Wazuh components, storage, access path, monitored workloads, and analyst workflow.

Platform Preparation

3. Preparing Kubernetes for Wazuh

Validate the Kubernetes lab before deploying Wazuh: nodes, storage, namespaces, resources, DNS, and baseline troubleshooting commands.

Wazuh Deployment

4. Deploying Wazuh on Kubernetes

Deploy Wazuh using the official Kubernetes flow with Windows/PowerShell notes, certificate generation, storage validation, and apply troubleshooting.

Kubernetes Troubleshooting

5. Troubleshooting Wazuh on Kubernetes

Use pods, PVCs, StorageClasses, services, endpoints, logs, and events to diagnose Wazuh deployment problems.

SIEM Operations

6. Understanding the Wazuh Components

Understand the Wazuh manager, indexer, dashboard, agents, services, StatefulSets, Deployments, persistent volumes, and secrets.

Dashboard Validation

7. Accessing and Validating the Wazuh Dashboard

Access the dashboard safely, validate Wazuh health, confirm services and endpoints, and prepare for SOC analyst workflow.

Kubernetes Agent Deployment

8. Deploying a Wazuh Agent DaemonSet

Deploy a real Wazuh agent DaemonSet, connect it to the Wazuh manager, validate enrollment, and document Kubernetes monitoring coverage.

Windows Host Agent

9. Installing a Wazuh Agent on the Windows Host

Install a Wazuh agent on the Windows host, use port-forwarding to reach the Kubernetes-hosted Wazuh manager, validate enrollment, and compare Windows host telemetry with Kubernetes telemetry.

Detection Testing

10. Generating Safe Security Events

Generate safe lab events that create useful SOC telemetry without teaching exploit behavior.

Alert Investigation

11. Investigating Alerts in Wazuh

Triage Wazuh alerts using timestamp, source, rule, severity, description, full log, scope, and recommended action.

Detection Engineering

12. Detection and Tuning Notes

Write practical detection notes, false-positive notes, tuning recommendations, and alert-quality observations.

Incident Response

13. SOC Incident Workflow

Turn an alert into a structured SOC investigation with triage, scope, evidence, impact, containment, remediation, and lessons learned.

Final Project

14. Final Project: Build and Operate a Kubernetes SOC Lab

Deploy the SOC lab, validate Wazuh, onboard Kubernetes and Windows host monitoring, generate test events, investigate alerts, write findings, and document cleanup.