- Public mini-SOC demo published through GitHub Pages.
- GitBook playbooks published for reviewer-friendly triage walkthroughs.
- Five lab-only Sigma correlations for Windows authentication anomalies.
- Synthetic validation fixtures with positive, negative, boundary and tuning cases.
- Reviewed Splunk conversion outputs and bilingual validation reports.
- CI gates for linting, tests, secret scanning, dependency audit and static demo publishing.
Public demo:
https://rubenasuasoto.github.io/windows-authentication-detection-lab/reports/latest/demo.html
GitBook documentation:
https://2dam-7.gitbook.io/window-auth/
Scope: defensive lab using synthetic data. No production logs, credentials, malware, offensive simulations or host-changing automation are included.