Operation Blue Sentinel
Cloud-Based Security Operations and Incident Response Lab
A security alert only matters if you can investigate and respond to it. Operation Blue Sentinel was a cloud-based SOC project where I worked with a three-member team to monitor security activity, investigate phishing and brute-force attacks, and coordinate incident response using Wazuh SIEM, GoPhish, and VirusTotal.

Objectives
- Build and operate a cloud-based SOC environment
- Gain practical experience with SIEM monitoring
- Detect and investigate suspicious security activity
- Investigate phishing and brute-force attacks
- Practice incident triage and response
- Use threat intelligence to support investigations
- Coordinate incident response within a team
- Document findings and recommended actions
Outcomes
- Built and defended a cloud-based SOC environment
- Used Wazuh SIEM for practical security monitoring
- Investigated phishing attack activity
- Investigated brute-force attack activity
- Used VirusTotal during threat investigations
- Practiced incident-response coordination
- Worked within a three-member SOC team
- Strengthened practical security analysis and documentation skills
Context
The project gave me a practical environment for understanding how a SOC works as a team. Instead of studying security monitoring only in theory, we worked through attack scenarios using cloud systems and security tools.
The Problem
Phishing and brute-force attacks can create several indicators across users, systems, and network activity. The project focused on turning those signals into useful findings rather than treating every alert as an isolated event.
Approach
The project followed a simple security operations approach: generate and observe suspicious activity, collect alerts through Wazuh, investigate the evidence, enrich findings where useful, coordinate the response, and document what was discovered.
Architecture / Workflow
↓
Security Events and Attack Activity
↓
Wazuh SIEM Monitoring
↓
Alert Triage
↓
Evidence Investigation
↓
Threat Intelligence Checks
↓
Incident Response
↓
Documentation and Team Review
Phishing and brute-force scenarios
↓
Events collected by the monitoring environment
↓
Wazuh generates security alerts
↓
Analysts review relevant logs and indicators
↓
VirusTotal supports indicator investigation
↓
Team assesses the incident
↓
Response actions and findings are documented
Implementation
I worked directly with the monitoring and investigation process rather than only observing the project. This included reviewing security activity, investigating phishing and brute-force events, coordinating response activities, and documenting findings with the team
Security Considerations
A major security consideration was keeping the exercises controlled. Phishing and attack scenarios were used for training and investigation, while monitoring and response activities stayed within the cloud lab environment.
Challenges
Another challenge was coordinating technical work across a team. During an investigation, different findings need to be shared clearly so that everyone understands what happened and what should be done next.
Lessons Learned
The project showed me how technical investigation and communication work together in incident response. Good SOC work depends on both understanding the security evidence and making sure the team has a clear picture of the incident.
Future Improvements
Future improvements could include additional SIEM detection rules, automated enrichment, more realistic attack scenarios, better dashboards, and repeatable incident-response procedures for different types of threats.
Technologies
Gallery
Capability Areas
Relevant Skills
Related Projects

IT Support Home Lab
A virtualised environment for practicing IT support, systems administration, Active Directory management, and network troubleshooting.

Network Troubleshooting Lab
A lab environment for practicing network configuration, troubleshooting, and security assessment using industry-standard tools.

VerifAI
AI-Powered Social Engineering Detection
Trust should be based on evidence, not hype. VerifAI is a Web3 security and trust intelligence platform that collects technical evidence from websites, GitHub repositories, smart contracts, DNS, domains, and TLS, then produces an explainable risk assessment backed by that evidence.