Project

Operation Blue Sentinel

Cloud-Based Security Operations and Incident Response Lab

A security alert only matters if you can investigate and respond to it. Operation Blue Sentinel was a cloud-based SOC project where I worked with a three-member team to monitor security activity, investigate phishing and brute-force attacks, and coordinate incident response using Wazuh SIEM, GoPhish, and VirusTotal.

Jun 2026 — Jul 2026 Cybersecurity & Threat Intelligence Incident Commander
Operation Blue Sentinel cloud-based SOC environment for security monitoring and incident response

Objectives

  • Build and operate a cloud-based SOC environment
  • Gain practical experience with SIEM monitoring
  • Detect and investigate suspicious security activity
  • Investigate phishing and brute-force attacks
  • Practice incident triage and response
  • Use threat intelligence to support investigations
  • Coordinate incident response within a team
  • Document findings and recommended actions

Outcomes

  • Built and defended a cloud-based SOC environment
  • Used Wazuh SIEM for practical security monitoring
  • Investigated phishing attack activity
  • Investigated brute-force attack activity
  • Used VirusTotal during threat investigations
  • Practiced incident-response coordination
  • Worked within a three-member SOC team
  • Strengthened practical security analysis and documentation skills

Context

Security operations require more than knowing individual tools. Analysts need to bring monitoring, investigation, communication, and response together when suspicious activity appears.

The project gave me a practical environment for understanding how a SOC works as a team. Instead of studying security monitoring only in theory, we worked through attack scenarios using cloud systems and security tools.

The Problem

Security teams receive alerts from different systems, but an alert does not automatically explain what happened. The challenge is to identify suspicious activity, collect enough evidence, understand the event, and decide how to respond.

Phishing and brute-force attacks can create several indicators across users, systems, and network activity. The project focused on turning those signals into useful findings rather than treating every alert as an isolated event.

Approach

We built a cloud-based SOC environment and used Wazuh SIEM as the central monitoring platform. GoPhish supported phishing scenarios, while VirusTotal provided additional threat intelligence during investigations.

The project followed a simple security operations approach: generate and observe suspicious activity, collect alerts through Wazuh, investigate the evidence, enrich findings where useful, coordinate the response, and document what was discovered.

Architecture / Workflow

Cloud SOC Environment

Security Events and Attack Activity

Wazuh SIEM Monitoring

Alert Triage

Evidence Investigation

Threat Intelligence Checks

Incident Response

Documentation and Team Review

Phishing and brute-force scenarios

Events collected by the monitoring environment

Wazuh generates security alerts

Analysts review relevant logs and indicators

VirusTotal supports indicator investigation

Team assesses the incident

Response actions and findings are documented

Implementation

The SOC environment used Microsoft Azure and Oracle Cloud Infrastructure to support the lab systems. Wazuh provided centralized security monitoring, GoPhish supported phishing exercises, and VirusTotal was used during threat investigation.

I worked directly with the monitoring and investigation process rather than only observing the project. This included reviewing security activity, investigating phishing and brute-force events, coordinating response activities, and documenting findings with the team

Security Considerations

The project emphasized monitoring, controlled attack simulation, evidence-based investigation, and documenting actions taken during an incident. Security testing was carried out within the project environment rather than against systems without authorization.

A major security consideration was keeping the exercises controlled. Phishing and attack scenarios were used for training and investigation, while monitoring and response activities stayed within the cloud lab environment.

Challenges

One challenge was separating useful security signals from events that did not require the same level of attention. Investigating alerts required looking beyond the initial notification and checking the surrounding evidence.

Another challenge was coordinating technical work across a team. During an investigation, different findings need to be shared clearly so that everyone understands what happened and what should be done next.

Lessons Learned

Security monitoring is not just watching a dashboard. An alert becomes useful only when it is investigated, connected to evidence, and followed by an appropriate response.

The project showed me how technical investigation and communication work together in incident response. Good SOC work depends on both understanding the security evidence and making sure the team has a clear picture of the incident.

Future Improvements

I would expand the environment with more attack scenarios, stronger detection rules, additional endpoint and network telemetry, and more structured incident-response playbooks.

Future improvements could include additional SIEM detection rules, automated enrichment, more realistic attack scenarios, better dashboards, and repeatable incident-response procedures for different types of threats.

Technologies

Wazuh SIEMGoPhishVirusTotalMicrosoft AzureOracle Cloud InfrastructureWindowsLinux

Gallery

Operation Blue Sentinel
Cloud-Based Security Operations and Incident Response Lab

Capability Areas

Cloud, Systems and IT InfrastructureCybersecurity & Threat Intelligence

Relevant Skills

GoPhishLinux AdministrationMicrosoft AzureOracle Cloud InfrastructureVirusTotalWazuh SIEMWindows Administration