Post

Home Lab

Overview

I am planning to combine all my scattered home lab setup into some niche architecture, which has both malware analysis/development and threat detection. I used one old Laptop and a Dell Micro. The specs are sufficient for my requirements. I’m using Proxmox for virtualization as it’s an open-source hypervisor and has all features like cloning, snapshot, backup, and network management.

Requirement

NameCoreRAM (GB)Disk (GB)Remark
Asus PN4128512Optional
Micro 30704321024Required
Laptop832512Required
RPi34116Optional
RPi34132Optional

Description

The Malware Lab setup includes Windows as the target machine, Active Directory, Windows machine with Flare and Sentinel configured and REMnux. Logs from all hosts will be forwarded to Wazuh and Splunk for Analysis and Detection. With Splunk, we can analyse all raw logs and Wazuh will be configured with Sigma/Yara for detection along with its native rule. Also, thinking of putting a network tap with Suricata.

This will get enhanced as we move forward and will write all the setup and configuration in a separate article.

This post is licensed under CC BY 4.0 by the author.