Build a hands-on SOC lab on Kubernetes using Wazuh.
A guided lab path for deploying Wazuh on Kubernetes, troubleshooting the platform, deploying Kubernetes and Windows host agents, generating safe security events, and using Wazuh from a SOC analyst perspective.
What this path is for
This lab series builds on Kubernetes Field Notes and uses Wazuh to create a practical SOC-style environment. The goal is to understand how Kubernetes operations, Wazuh deployment, agent enrollment, SIEM visibility, endpoint monitoring, alert triage, detection notes, incident workflow, and cleanup fit together.
Prerequisites from Kubernetes Field Notes
- Setting Up a Local Kubernetes Lab
- Namespaces
- Persistent Storage
- ServiceAccounts and RBAC
- NetworkPolicies
- Observability
- Kubernetes Troubleshooting Playbook
Recommended path
Work through these lessons in order. The path starts with SOC concepts, moves into Wazuh-on-Kubernetes deployment and troubleshooting, then adds Kubernetes and Windows endpoint monitoring before moving into safe event generation, alert investigation, detection notes, and incident workflow.
1. What a SOC Lab Actually Is
Define SOC, SIEM, XDR, telemetry, alerts, triage, investigations, findings, and the purpose of a safe lab.
2. Kubernetes SOC Lab Architecture
Design the lab namespaces, Wazuh components, storage, access path, monitored workloads, and analyst workflow.
3. Preparing Kubernetes for Wazuh
Validate the Kubernetes lab before deploying Wazuh: nodes, storage, namespaces, resources, DNS, and baseline troubleshooting commands.
4. Deploying Wazuh on Kubernetes
Deploy Wazuh using the official Kubernetes flow with Windows/PowerShell notes, certificate generation, storage validation, and apply troubleshooting.
5. Troubleshooting Wazuh on Kubernetes
Use pods, PVCs, StorageClasses, services, endpoints, logs, and events to diagnose Wazuh deployment problems.
6. Understanding the Wazuh Components
Understand the Wazuh manager, indexer, dashboard, agents, services, StatefulSets, Deployments, persistent volumes, and secrets.
7. Accessing and Validating the Wazuh Dashboard
Access the dashboard safely, validate Wazuh health, confirm services and endpoints, and prepare for SOC analyst workflow.
8. Deploying a Wazuh Agent DaemonSet
Deploy a real Wazuh agent DaemonSet, connect it to the Wazuh manager, validate enrollment, and document Kubernetes monitoring coverage.
9. Installing a Wazuh Agent on the Windows Host
Install a Wazuh agent on the Windows host, use port-forwarding to reach the Kubernetes-hosted Wazuh manager, validate enrollment, and compare Windows host telemetry with Kubernetes telemetry.
10. Generating Safe Security Events
Generate safe lab events that create useful SOC telemetry without teaching exploit behavior.
11. Investigating Alerts in Wazuh
Triage Wazuh alerts using timestamp, source, rule, severity, description, full log, scope, and recommended action.
12. Detection and Tuning Notes
Write practical detection notes, false-positive notes, tuning recommendations, and alert-quality observations.
13. SOC Incident Workflow
Turn an alert into a structured SOC investigation with triage, scope, evidence, impact, containment, remediation, and lessons learned.
14. Final Project: Build and Operate a Kubernetes SOC Lab
Deploy the SOC lab, validate Wazuh, onboard Kubernetes and Windows host monitoring, generate test events, investigate alerts, write findings, and document cleanup.