faid.alani
← all posts

> homelab

Building My Homelab SOC on Proxmox

How I turned one server into a small company network with Active Directory, a SIEM, and something to attack it.

Faid Al-Ani7 min read

Reading about detection only gets you so far. I wanted a place where I could build a network, break it, and watch the logs light up, the same loop a SOC analyst runs every shift. So I built a small fake company inside Proxmox.

Why Proxmox

Proxmox VE is free, runs VMs and containers side by side, and makes snapshots easy. That last part matters: when an attack simulation leaves a VM in a bad state, I roll it back in seconds instead of rebuilding.

Storage is two 256 GB Gen 3 NVMe SSDs with separate jobs: one for the Proxmox boot drive and one for VM storage. Keeping them apart means a full VM disk can't take the hypervisor down with it.

The network

proxmox-ve
├── DC01      Windows Server · AD DS, DNS, DHCP, Group Policy
├── ADMIN01   Admin workstation
├── WS-*      Domain-joined user workstations
├── WAZUH     SIEM · agent log collection and alerting
├── NESSUS    Vulnerability scanning
├── KALI      Attack simulation
└── DNS/VPN   Pi-hole, AdGuard, Tailscale
ComponentRoleWhy it's here
Windows Server ADIdentityAlmost every company I'd defend runs on Active Directory
WazuhSIEMCollects endpoint logs and raises alerts I can triage
NessusVuln scanningFinds what needs patching before an attacker does
Kali LinuxAttackerGenerates real attack traffic for Wazuh to catch
Pi-hole / AdGuardDNS filteringDNS visibility and ad/tracker blocking
TailscaleRemote accessReach the lab securely without opening ports

Locking down access with Group Policy

I set access up the way I'd want it in a real office:

  • The admin01 account gets local admin on every workstation except the domain controller.
  • Regular users can sign in to any workstation but not the domain controller or the admin machine.

The point is least privilege. If a regular user's password gets phished, the attacker lands on a workstation with no path to the DC through that account.

Watching attacks happen

With Wazuh agents on the Windows machines, I run activity from Kali and check what shows up in the dashboard. When I need to go deeper than the alerts, I pull a packet capture and work through it in Wireshark with the same order every time: protocol hierarchy, conversations, targeted filters, DNS, then endpoints.

What's next

  • Deploy Sophos Firewall Home Edition as the lab's perimeter
  • Set up DHCP failover
  • Write and push an Acceptable Use Policy through the domain
  • Stand up DVWA and OWASP Juice Shop for web app testing

If you're building your own lab: start small. One domain controller, one workstation, and a SIEM teach you more than ten VMs you never look at.