Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Built a Blue Team Infrastructure Lab (pfSense, Suricata, ELK Stack in VMware)

0
Medium
Security-newscybersecurityreddit
Published: 07/20/2026 (07/20/2026, 08:53:54 UTC)
Source: Reddit Cybersecurity

Description

This is a shared project describing the setup of a Blue Team infrastructure lab using pfSense firewall, Suricata IDS/IPS, and ELK Stack for SIEM monitoring within a VMware virtualized environment. The lab demonstrates network segmentation, intrusion detection and prevention, and centralized log analysis for educational and practical cybersecurity defense purposes. No actual vulnerability or exploit is reported.

Reddit Discussion

r/cybersecurity·posted by u/umid_guluzada
00

Hey everyone,

I wanted to share my latest hands-on Blue Team lab project focused on centralized network security, IDS/IPS, and SIEM monitoring.

Lab Architecture & Tech Stack:

pfSense: Acts as the firewall and router, handling network segmentation.

Suricata: Configured for intrusion detection and prevention (IDS/IPS).

ELK Stack (Ubuntu Server): Collects, analyzes, and visualizes security logs via Kibana.

Environment: Virtualized using VMware with a dedicated victim (Windows) and attacker (Kali Linux) setup.

The project has significantly helped me understand network traffic monitoring and log analysis. You can check out the full technical documentation, architecture diagrams, and setup details on my GitHub:

🔗 GitHub Repository: https://github.com/umidguluzada/CyberDefense-Lab

I would love to hear your feedback, suggestions, or ideas for the next steps!

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/20/2026, 08:56:43 UTC

Technical Analysis

The provided content details a hands-on cybersecurity lab project that integrates pfSense as a firewall/router, Suricata configured in inline IPS mode for threat detection and blocking, and an ELK Stack server for log collection and visualization. The environment is virtualized with segregated attacker and victim subnets to simulate network defense scenarios. The project focuses on monitoring network traffic, detecting scans and brute-force attacks, and automating blocking of malicious IPs. It is intended as an educational resource rather than a report of a security vulnerability or threat.

Potential Impact

No security vulnerability or exploit is described. The content does not indicate any risk or impact to real systems but rather provides a lab setup for defensive cybersecurity training and experimentation.

Mitigation Recommendations

Not applicable. This is an educational lab project and not a security threat or vulnerability requiring remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a5de2c62a4a8d5989bc1482

Added to database: 07/20/2026, 08:56:38 UTC

Last enriched: 07/20/2026, 08:56:43 UTC

Last updated: 07/21/2026, 00:56:49 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses