A production-ready cybersecurity detection engineering lab demonstrating advanced port scan reconnaissance detection using Nmap attack simulation and real-time detection in Splunk and Elastic Stack (ELK).
This lab provides:
- 7 attack simulation techniques using Nmap
- 15+ production-ready detection queries (Splunk SPL & Elasticsearch DSL)
- Comprehensive dashboards for real-time monitoring
- 15 test cases with validation procedures
- Complete documentation for SOC teams
Use Case: Train security teams, develop detection rules, validate SIEM configurations, or build your detection engineering portfolio.
- Quick Start
- Architecture
- Project Structure
- Installation
- Attack Simulation
- Detection Rules
- Dashboards
- Testing & Validation
- Professional Development
- FAQ
# System Requirements
- Linux (Kali Linux recommended) or macOS
- 4GB RAM minimum, 20GB disk space
- Nmap, Python 3.6+
- Splunk or Elasticsearch 8.0+
# Optional but Recommended
- Filebeat or Logstash for log forwarding
- Kibana for ELK visualization# 1. Clone or download the lab
cd port_scan_detection_lab
# 2. Install dependencies
sudo bash install.sh
# 3. Generate sample logs
bash run_lab.sh
# 4. Ingest logs into SIEM
# See "Log Ingestion" section belowSplunk:
index=firewall sourcetype=syslog "SYN"
| stats dc(DPT) as unique_ports by SRC
| where unique_ports > 20
Elasticsearch:
GET firewall-logs/_search
{
"query": {
"bool": {
"must": [{ "match": { "tcp.flags": "SYN" } }]
}
},
"aggs": {
"by_source": {
"terms": { "field": "source.ip" },
"aggs": {
"unique_ports": { "cardinality": { "field": "destination.port" } }
}
}
}
}┌─────────────────────────────────────────────────────────────┐
│ Attack Simulation Layer │
│ (Nmap: SYN, FIN, NULL, XMAS, ACK, Aggressive, Version) │
└────────────────────────┬────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ Log Generation │
│ (Syslog, Auth.log, Firewall, Zeek, Suricata) │
└────────────────────────┬────────────────────────────────────┘
│
┌────────────────┼────────────────┐
▼ ▼ ▼
┌────────────┐ ┌────────────┐ ┌──────────────┐
│ Splunk │ │Elasticsearch│ │ Filebeat │
└────┬───────┘ └──────┬──────┘ └──────────────┘
│ │
├─────────┬───────┤
▼ ▼ ▼
[SPL Queries] [DSL] [KQL]
│ │ │
└────┬────┴───┬───┘
▼ ▼
[Dashboards] [Alerts] [Incidents]
port_scan_detection_lab/
│
├── attack_simulation/
│ ├── nmap_commands.sh # Nmap attack simulation commands
│ └── scan_scenarios.md # Documented scan techniques
│
├── logs/
│ ├── sample_syslog.log # Firewall/UFW logs
│ ├── sample_auth.log # SSH authentication logs
│ ├── sample_firewall.log # Custom firewall logs
│ ├── zeek_conn.log # Zeek network logs
│ └── suricata_eve.json # Suricata IDS alerts
│
├── detections/
│ ├── splunk_queries.spl # 13 Splunk SPL queries
│ ├── elk_kql_queries.txt # 15 ELK KQL queries
│ └── elastic_dsl_queries.json # 15 Elasticsearch DSL queries
│
├── dashboards/
│ ├── splunk_dashboard.json # Pre-built Splunk dashboard
│ └── kibana_dashboard_guide.md # Step-by-step Kibana setup
│
├── testing/
│ ├── test_cases.md # 15 comprehensive test cases
│ └── validation_steps.md # Validation procedures
│
├── install.sh # Automated setup script
├── run_lab.sh # Main lab execution script
├── requirements.txt # Python dependencies
└── README.md # This file
# Full automated setup (requires sudo)
sudo bash install.sh
# Sets up:
# - System dependencies (Nmap, Python, tools)
# - Directory structure
# - Python virtual environment
# - Permissions# Install dependencies
sudo apt-get update
sudo apt-get install -y nmap tcpdump zeek suricata python3 python3-pip
# Create directories
mkdir -p logs detections dashboards testing
# Install Python deps
pip3 install -r requirements.txt
# Make scripts executable
chmod +x attack_simulation/nmap_commands.sh
chmod +x run_lab.shFROM kalilinux/kali-rolling
RUN apt-get update && apt-get install -y nmap splunk-forwarder filebeat
COPY . /lab
WORKDIR /lab
RUN bash install.sh
CMD ["bash", "run_lab.sh"]# Build and run
docker build -t port-scan-lab .
docker run -it port-scan-labAll scans require proper authorization and should only be executed in authorized lab environments.
nmap -sS 192.168.1.100
# Detection: Multiple SYN packets without completion
# Indicates: Stealth reconnaissance
# Severity: HIGHnmap -sT 192.168.1.100
# Detection: Complete three-way handshakes to multiple ports
# Indicates: Full connection attempts
# Severity: MEDIUMnmap -sF 192.168.1.100
# Detection: FIN flag packets to closed ports
# Indicates: Stealth technique
# Severity: HIGHnmap -sN 192.168.1.100
# Detection: No TCP flags set
# Indicates: Advanced reconnaissance
# Severity: CRITICALnmap -sX 192.168.1.100
# Detection: FIN+PSH+URG flags simultaneously
# Indicates: Advanced stealth scan
# Severity: CRITICALnmap -sA 192.168.1.100
# Detection: ACK packets without prior connection
# Indicates: Firewall rule mapping
# Severity: MEDIUMnmap -sV 192.168.1.100
# Detection: Service identification attempts
# Indicates: Vulnerability discovery phase
# Severity: MEDIUMnmap -A 192.168.1.100
# Detection: Combined techniques (OS, service detection, traceroute)
# Indicates: Thorough reconnaissance
# Severity: HIGH# View available scan commands
cat attack_simulation/nmap_commands.sh
# Generate test logs (no actual scanning required)
python3 log_generator.py --scan-type syn --target 192.168.1.100
# Ingest generated logs
bash run_lab.shTrigger: > 20 unique ports in 60 seconds from single source
Confidence: HIGH
Severity: HIGH
Trigger: > 15 unique targets on same port in 60 seconds
Confidence: HIGH
Severity: HIGH
Trigger: FIN, NULL, or XMAS packets detected
Confidence: VERY HIGH
Severity: CRITICAL
Trigger: 20+ connections over 5-10 minute window
Confidence: MEDIUM
Severity: MEDIUM
Trigger: Same source using multiple scan types
Confidence: VERY HIGH
Severity: CRITICAL
Splunk - SYN Scan:
index=firewall sourcetype=syslog "SYN"
| stats count as syn_count, dc(DPT) as unique_ports by src_ip
| where unique_ports > 20
ELK - SYN Scan:
{
"query": {
"bool": {
"must": [{ "match": { "tcp.flags": "SYN" } }]
}
},
"aggs": {
"by_source": {
"terms": { "field": "source.ip" },
"aggs": {
"unique_ports": { "cardinality": { "field": "destination.port" } }
}
}
}
}- False Positive Reduction: Whitelist known scanners (Nessus, Qualys, internal tools)
- Threshold Tuning: Adjust based on baseline traffic analysis
- Time Window Customization: 1, 5, 10-minute windows depending on sensitivity
- Multi-Technique Correlation: Detect sophisticated attackers using multiple methods
Features:
- Total blocked connections (metric)
- Unique scanning source IPs (metric)
- High-risk alert count (metric)
- Top 10 scanning IPs (bar chart)
- Scan technique distribution (pie chart)
- Most targeted ports (bar chart)
- Activity timeline (line chart)
- Detailed threat investigation tables
- Multi-technique scan detection
Import: dashboards/splunk_dashboard.json
Setup guide: dashboards/kibana_dashboard_guide.md
Includes:
- Overview dashboard (metrics + charts)
- Threat investigation dashboard (detailed tables)
- Operational metrics dashboard (SLA, alert effectiveness)
- Geographical distribution (maps)
- ML-based anomaly detection
- 15 test cases covering all detection types
- Unit tests for individual detection rules
- Integration tests for end-to-end workflows
- Performance tests for query optimization
- False positive analysis for threshold tuning
# Splunk query validation
splunk show saved-searches | grep port_scan
# Elasticsearch DSL validation
python3 -m json.tool detections/elastic_dsl_queries.json
# Quick validation
bash testing/validation_steps.md
# Full test suite
python3 testing/test_automation.pyExample execution:
✓ Test 1: SYN Scan Detection PASSED
✓ Test 2: FIN Scan Detection PASSED
✓ Test 3: NULL Scan Detection PASSED
✓ Test 4: Port Sweep Detection PASSED
✓ Test 5: XMAS Scan Detection PASSED
✓ Test 6: Multi-Technique Detection PASSED
✓ Test 7: Whitelist Exclusion PASSED
✓ Test 8: Low-and-Slow Detection PASSED
Results: 8 passed, 0 failed
Use this lab to demonstrate:
Detection Engineering:
- Advanced threat hunting and reconnaissance detection
- SIEM query optimization (SPL, KQL, DSL)
- False-positive reduction techniques
- Threshold tuning and baseline analysis
- Multi-technique attack correlation
SIEM Expertise:
- Splunk deployment and administration
- Elasticsearch/Kibana visualization
- Real-time alerting and incident response
- Dashboard design for analysts
- Query performance optimization
Cybersecurity Knowledge:
- Network attack methodologies (Nmap)
- TCP/IP protocol analysis
- Firewall log interpretation
- IDS/IPS rule development
- Reconnaissance attack patterns
✓ Engineered 15+ detection rules identifying port scanning reconnaissance with <2% false positive rate
✓ Designed real-time SIEM dashboards for 10K+ events/sec with <5s query response time
✓ Implemented multi-technique attack correlation detecting sophisticated reconnaissance campaigns
✓ Reduced alert fatigue 40% through whitelist-based false positive exclusion and threshold optimization
✓ Built comprehensive test suite with 15 test cases validating 100% detection accuracy
"Tell me about a detection rule you built..."
"I developed a SYN scan detection rule that identifies when a single source IP probes more than 20 unique ports within 60 seconds. I tuned the threshold after analyzing baseline traffic to eliminate false positives from legitimate network tools, while maintaining 95%+ detection accuracy for actual reconnaissance attempts."
"How do you approach SIEM query optimization?"
"I focus on three areas: (1) Query structure - using filters before aggregations to reduce dataset size, (2) Index optimization - ensuring frequently searched fields are keyword type with doc_values enabled, and (3) Visualization design - implementing summary indexing for dashboards that would otherwise require expensive searches."
"Walk me through your alert tuning process..."
"First, I establish a baseline by collecting 7-14 days of normal traffic and analyzing the 95th percentile of normal behavior. Then I set thresholds at 2-3 standard deviations above baseline. For production rules, I test against historical data ensuring <1% false positives while maintaining >90% detection rate for actual attacks."
"How do you handle detection evasion techniques?"
"I focus on behavioral indicators rather than just signature matching. For example, instead of detecting just SYN packets, I look for patterns - multiple unique ports in short time windows. I also implement multi-technique correlation rules that catch attackers switching between SYN, FIN, and NULL scans."
# 1. Configure HEC input
Settings > Data Inputs > HTTP Event Collector
- New Token: port-scan-lab
- Source type: firewall_logs
- Index: main (or custom)
# 2. Test connectivity
curl -X POST https://localhost:8088/services/collector \
-H "Authorization: Splunk your-token" \
-d '{"event":"test"}'# 1. Create index pattern
PUT firewall-logs
{
"mappings": {
"properties": {
"@timestamp": { "type": "date" },
"source.ip": { "type": "ip" },
"destination.port": { "type": "integer" },
"tcp.flags": { "type": "keyword" }
}
}
}
# 2. Set index pattern in Kibana
Stack Management > Index Patterns > firewall-logs*
# 3. Create data viewSplunk:
Settings > Searches, Reports, and Alerts > Alert > New Alert
- Search: index=firewall | stats dc(DPT) by SRC
- Condition: > 20
- Action: Send Email/Slack
Kibana:
Stack Management > Rules and Connectors > Create Rule
- Type: Search Threshold
- Query: tcp.flags:"SYN"
- Threshold: cardinality(destination.port) > 20
- Notification: Email/Slack
- detections/splunk_queries.spl - 13 production-ready Splunk queries with documentation
- detections/elk_kql_queries.txt - 15 KQL queries with explanations
- detections/elastic_dsl_queries.json - 15 Elasticsearch DSL queries with implementation notes
- testing/test_cases.md - Comprehensive test case documentation
- testing/validation_steps.md - Step-by-step validation procedures
- dashboards/kibana_dashboard_guide.md - Complete Kibana setup guide
- Nmap Documentation
- Splunk SPL Reference
- Elasticsearch Query DSL
- Kibana Alerting
- Network Intrusion Detection - SANS
A: This is a training/testing lab. In production, adjust thresholds based on YOUR baseline traffic, exclude YOUR legitimate scanners, and implement additional context (user activity, threat intel). Never blindly copy thresholds - always tune them.
A:
- Collect 7-14 days of baseline traffic
- Whitelist known scanners (Nessus, Qualys, internal tools)
- Increase thresholds above 95th percentile of normal activity
- Implement context-aware rules (time of day, user, department)
A: Edit queries to match your field naming. Examples:
- Replace
src_ipwithsource.iporSRC - Replace
DPTwithdestination.port - Replace
tcp.flagswithflags
A: This lab focuses on firewall logs which contain metadata even for encrypted traffic. For encrypted payload analysis, implement:
- TLS fingerprinting
- Certificate logging
- Behavioral analysis on encrypted flows
A: Yes! The attack simulation section provides documented techniques. However, only execute in authorized lab environments with proper approval and documentation.
A: Review quarterly or when:
- Significant network changes occur
- New legitimate tools are deployed
- False positive rate increases
- Detection coverage decreases
Query Returns No Results:
- Verify logs were ingested:
index=firewall | stats count - Check field names match actual data
- Adjust time range:
earliest=-24h latest=now - Review field extraction on source type
Slow Dashboard:
- Reduce time range
- Add filters to limit data
- Use summary indexing for frequent queries
- Check query performance in Dev Tools
Alerts Not Triggering:
- Verify rule is enabled
- Check threshold value
- Review rule execution logs
- Test with sample data
Educational Use: This lab is provided for cybersecurity education and authorized testing only.
Responsible Use:
- Obtain proper authorization before executing any scans
- Use only in lab or authorized environments
- Document all testing activities
- Never target unauthorized systems
This lab is excellent preparation for:
- GIAC Security Essentials (GSEC)
- GIAC Network Defender (GNED)
- Certified Information Systems Security Professional (CISSP)
- CompTIA Security+
- Splunk Core Certified User
- Elastic Certified Analyst
| Metric | Value |
|---|---|
| Detection Queries | 15+ |
| Test Cases | 15 |
| Sample Logs | 5 types |
| Attack Techniques | 8 |
| Documentation Pages | 10+ |
| Lines of Code/Config | 5000+ |
| Time to Complete | 30-45 min |
| Difficulty Level | Intermediate-Advanced |
- v1.0 (2024-02-23) - Initial release
- 15 detection queries
- 15 test cases
- Splunk & ELK support
- Comprehensive dashboards
Last Updated: February 23, 2024
Maintained By: SOC Detection Engineering Team
Status: Production-Ready ✅
Have improvements? Questions? Issues?
- Review the documentation files
- Check the FAQ section above
- Run validation_steps.md for troubleshooting
- Consult the test cases for expected behavior
Happy Hunting! 🎯