A home lab demonstrating layered defense: a perimeter firewall (pfSense) filters traffic at the network edge, while a SIEM/XDR agent (Wazuh) catches whatever makes it past the perimeter on the protected host. The project shows how the same incident is visible from two different layers of the infrastructure — the network perimeter and the endpoint — and how these two log sources complement each other.
[External source] --> WAN --> [pfSense] --> LAN --> [Ubuntu Agent + Wazuh Agent]
|
| reports to
v
[Wazuh Manager (Docker)]
- pfSense — perimeter gateway/firewall between the external network (WAN) and the protected segment (LAN). Logs and blocks unwanted traffic at the edge.
- Wazuh Agent — installed on the protected Linux host (Ubuntu) inside the LAN segment. Tracks authentication attempts, file integrity (FIM), system configuration.
- Wazuh Manager — SIEM/XDR platform (built on the Elastic/ELK stack), deployed via Docker on a separate Linux machine. Collects and analyzes events from all agents, provides a web dashboard for investigation.
Detailed technical write-ups for each component: docs/pfsense.md and docs/wazuh.md.
| Component | Technology |
|---|---|
| Firewall / Gateway | pfSense CE 2.8.0 |
| SIEM / XDR | Wazuh 4.14.6 (manager + indexer + dashboard) |
| Containerization | Docker + Docker Compose |
| Host OS | Ubuntu Server 24.04 LTS, Ubuntu Desktop 26.04 |
| Virtualization | Oracle VirtualBox |
| Attack tooling | Nmap, Hydra (SSH brute-force) |
Three separate virtual machines on an isolated lab network.
Three running VMs: pfSense (gateway), Wazuh Manager (Ubuntu Server), Wazuh Agent (Ubuntu Desktop).
-
pfSense VM — two network adapters:
- WAN (bridged, facing the external network)
- LAN (Internal Network, the isolated protected segment)
WAN and LAN interfaces assigned on the pfSense console, with the pfSense web login reachable from the Ubuntu Agent VM on the LAN side.
-
Ubuntu Agent VM — sits in the LAN segment behind pfSense; all outbound traffic goes only through the gateway. Runs the Wazuh Agent.
-
Wazuh Manager VM — a separate Linux machine running the Wazuh Docker stack (manager, indexer, dashboard).
Wazuh Manager, Indexer and Dashboard containers up via docker compose.
The scenario simulates an external attacker probing the perimeter, brute-forcing SSH through the one exposed port, and gaining access — illustrating detection at both the firewall and the endpoint level.
Full port scan (nmap -p- -Pn) shows only port 2222/tcp open — everything else is filtered by the default-deny firewall rule.
Firewall log showing the scan traffic dropped by the default deny rule on WAN, timestamped to match the Nmap run above.
Hydra dictionary attack against ssh://<WAN-IP>:2222 — a valid password is found.
Wazuh's Threat Hunting view shows a spike of sshd: authentication failed events, aggregated into a higher-severity Multiple authentication failures alert (rule 40111, level 10) — the SIEM correlating many low-level failures into one actionable event.
After recovering the password via brute-force, the attacker logs in over SSH and attempts a file-system action (touch on a file under a monitored path). In a real intrusion, this is the stage where an attacker would modify configuration, plant persistence, or access data on the host — and it is exactly the kind of activity Wazuh's File Integrity Monitoring (FIM) module is designed to catch, independently of whatever happened at the network layer.
Wazuh dashboard confirming the agent is active, with systemctl status wazuh-agent on the endpoint showing the agent process tree running.
- Layered defense: the same intrusion attempt produces distinct, complementary evidence at two different layers — the firewall sees and blocks reconnaissance traffic; the endpoint agent sees and correlates the authentication attack that got through the one open port.
- Correlation over time: firewall log timestamps and Wazuh alert timestamps line up with the actual attack timeline (recon → block → brute-force → detection), without needing a single unified log pipeline (see Future Work).
- Practical infrastructure troubleshooting: getting Wazuh Manager, Agent, and pfSense to talk to each other across bridged/NAT VirtualBox networking surfaced and resolved several real networking issues — documented in
docs/wazuh.md.
.
├── README.md
├── LICENSE
├── docs/
│ ├── pfsense.md # pfSense technical setup
│ ├── wazuh.md # Wazuh technical setup
│ └── screenshots/ # all screenshots referenced above
└── attack-simulation/
└── passwords.txt # wordlist used for the SSH brute-force demo
- Forward pfSense firewall logs to Wazuh via syslog for single-pane correlation instead of manual timestamp matching across two dashboards.
- Deploy a deliberately vulnerable web app on the Ubuntu Agent to extend the scenario beyond SSH brute-force.
See LICENSE.








