> homelab
Building My Homelab SOC on Proxmox
How I turned one server into a small company network with Active Directory, a SIEM, and something to attack it.
Reading about detection only gets you so far. I wanted a place where I could build a network, break it, and watch the logs light up, the same loop a SOC analyst runs every shift. So I built a small fake company inside Proxmox.
Why Proxmox
Proxmox VE is free, runs VMs and containers side by side, and makes snapshots easy. That last part matters: when an attack simulation leaves a VM in a bad state, I roll it back in seconds instead of rebuilding.
Storage is two 256 GB Gen 3 NVMe SSDs with separate jobs: one for the Proxmox boot drive and one for VM storage. Keeping them apart means a full VM disk can't take the hypervisor down with it.
The network
proxmox-ve
├── DC01 Windows Server · AD DS, DNS, DHCP, Group Policy
├── ADMIN01 Admin workstation
├── WS-* Domain-joined user workstations
├── WAZUH SIEM · agent log collection and alerting
├── NESSUS Vulnerability scanning
├── KALI Attack simulation
└── DNS/VPN Pi-hole, AdGuard, Tailscale
| Component | Role | Why it's here |
|---|---|---|
| Windows Server AD | Identity | Almost every company I'd defend runs on Active Directory |
| Wazuh | SIEM | Collects endpoint logs and raises alerts I can triage |
| Nessus | Vuln scanning | Finds what needs patching before an attacker does |
| Kali Linux | Attacker | Generates real attack traffic for Wazuh to catch |
| Pi-hole / AdGuard | DNS filtering | DNS visibility and ad/tracker blocking |
| Tailscale | Remote access | Reach the lab securely without opening ports |
Locking down access with Group Policy
I set access up the way I'd want it in a real office:
- The
admin01account gets local admin on every workstation except the domain controller. - Regular users can sign in to any workstation but not the domain controller or the admin machine.
The point is least privilege. If a regular user's password gets phished, the attacker lands on a workstation with no path to the DC through that account.
Watching attacks happen
With Wazuh agents on the Windows machines, I run activity from Kali and check what shows up in the dashboard. When I need to go deeper than the alerts, I pull a packet capture and work through it in Wireshark with the same order every time: protocol hierarchy, conversations, targeted filters, DNS, then endpoints.
What's next
- Deploy Sophos Firewall Home Edition as the lab's perimeter
- Set up DHCP failover
- Write and push an Acceptable Use Policy through the domain
- Stand up DVWA and OWASP Juice Shop for web app testing
If you're building your own lab: start small. One domain controller, one workstation, and a SIEM teach you more than ten VMs you never look at.