How to Build a SOC Home Lab (Elastic SIEM) | Practical Demo with Pratyush

How to Build a SOC Home Lab (Elastic SIEM) | Practical Demo with Pratyush

🎙 Prabh Nair (with guest Pratyush Joshi) 👥 184K 📅 March 11, 2026 ⏱ 65 min 👁 5K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

SOCElastic StackSysmonWinLogBeatAtomic Red Team

Summary

In this episode, Prabh Nair interviews Pratyush Joshi, an associate security engineer, to discuss SOC architecture and provide a practical demonstration of building a SOC home lab using open-source tools. The video covers the end-to-end workflow of a SOC, from log collection to alert investigation. Pratyush explains the roles of Elasticsearch, Kibana, and Logstash in the ELK stack, and demonstrates how to configure them on an Ubuntu VM. He then shows how to set up Windows telemetry using Sysmon and WinLogBeat to ship logs to Elasticsearch. The demo includes simulating attacks with Atomic Red Team, which executes MITRE ATT&CK techniques, and then creating detection rules in Kibana to generate alerts. The video also discusses SOC career paths, highlighting the tiers (L1, L2) and the skills needed to succeed. Pratyush emphasizes the importance of hands-on practice and building a home lab to gain practical experience. He provides tips on writing queries, creating detection rules, and using dashboards for monitoring. The episode concludes with advice for freshers on how to become SOC-ready, including using platforms like Let’s Defend and practicing with Sigma rules.

181 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high practical value for beginners and aspiring SOC analysts. It offers a step-by-step guide to building a SOC home lab, which is a hands-on way to learn cybersecurity skills. The argumentation is solid, as Pratyush demonstrates each step live, showing real logs and alerts. The discussion on SOC architecture and career paths is informative and grounded in real-world experience. The emphasis on practical skills and home labs is well-supported by the demo, making the case for hands-on learning compelling.

Scientific Rigor, Source Quality, Title Accuracy

The video is scientifically rigorous in its practical approach, but it lacks formal citations. The sources mentioned are open-source tools like Elastic Stack, Sysmon, WinLogBeat, and Atomic Red Team, which are well-known and reputable. The title accurately reflects the content, and the video stays on topic throughout. The demonstration is clear and reproducible, which adds to its credibility. However, the video does not provide references to academic papers or official documentation, which could enhance its scientific rigor.

174 words

Title / Content Match

The title accurately reflects the content: a practical demo of building a SOC home lab using Elastic SIEM.

Quality & Reliability

8/10

The video provides a practical, step-by-step tutorial on building a SOC home lab using Elastic SIEM, Sysmon, WinLogBeat, and Atomic Red Team. The instructions are clear and based on real-world experience, with a live demo. The content is accurate and aligns with industry practices, though it lacks formal citations and some advanced topics are simplified.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The video provides a comprehensive, hands-on tutorial for building a SOC home lab using open-source tools, which is a valuable resource for beginners. It bridges the gap between theoretical knowledge and practical application, offering a step-by-step guide that viewers can replicate. The inclusion of a live demo with real logs and alerts enhances its educational value.

Pour aller plus loin :

105 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a slightly lower score in technical level, indicating that the video is informative and reliable but may not delve into advanced technical details. The overall high scores suggest a well-rounded educational resource.

Reliability 8/10

💬 No comments were provided for analysis.