Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

pfSense + Wazuh SOC Lab — Layered Detection

pfSense Wazuh Docker VirtualBox Ubuntu SSH Nmap Hydra

A home lab demonstrating layered defense: a perimeter firewall (pfSense) filters traffic at the network edge, while a SIEM/XDR agent (Wazuh) catches whatever makes it past the perimeter on the protected host. The project shows how the same incident is visible from two different layers of the infrastructure — the network perimeter and the endpoint — and how these two log sources complement each other.

Concept

[External source] --> WAN --> [pfSense] --> LAN --> [Ubuntu Agent + Wazuh Agent]
                                      |
                                      | reports to
                                      v
                          [Wazuh Manager (Docker)]
  • pfSense — perimeter gateway/firewall between the external network (WAN) and the protected segment (LAN). Logs and blocks unwanted traffic at the edge.
  • Wazuh Agent — installed on the protected Linux host (Ubuntu) inside the LAN segment. Tracks authentication attempts, file integrity (FIM), system configuration.
  • Wazuh Manager — SIEM/XDR platform (built on the Elastic/ELK stack), deployed via Docker on a separate Linux machine. Collects and analyzes events from all agents, provides a web dashboard for investigation.

Detailed technical write-ups for each component: docs/pfsense.md and docs/wazuh.md.


Tech Stack

Component Technology
Firewall / Gateway pfSense CE 2.8.0
SIEM / XDR Wazuh 4.14.6 (manager + indexer + dashboard)
Containerization Docker + Docker Compose
Host OS Ubuntu Server 24.04 LTS, Ubuntu Desktop 26.04
Virtualization Oracle VirtualBox
Attack tooling Nmap, Hydra (SSH brute-force)

Lab Environment

Three separate virtual machines on an isolated lab network.

VirtualBox VMs

Three running VMs: pfSense (gateway), Wazuh Manager (Ubuntu Server), Wazuh Agent (Ubuntu Desktop).

  1. pfSense VM — two network adapters:

    • WAN (bridged, facing the external network)
    • LAN (Internal Network, the isolated protected segment)

    pfSense interface assignment

    WAN and LAN interfaces assigned on the pfSense console, with the pfSense web login reachable from the Ubuntu Agent VM on the LAN side.

  2. Ubuntu Agent VM — sits in the LAN segment behind pfSense; all outbound traffic goes only through the gateway. Runs the Wazuh Agent.

  3. Wazuh Manager VM — a separate Linux machine running the Wazuh Docker stack (manager, indexer, dashboard).

Wazuh stack running

Wazuh Manager, Indexer and Dashboard containers up via docker compose.


Attack Scenario

The scenario simulates an external attacker probing the perimeter, brute-forcing SSH through the one exposed port, and gaining access — illustrating detection at both the firewall and the endpoint level.

1. Reconnaissance — port scan against the pfSense WAN address

Nmap scan

Full port scan (nmap -p- -Pn) shows only port 2222/tcp open — everything else is filtered by the default-deny firewall rule.

2. Perimeter defense — pfSense blocking the scan

pfSense firewall log

Firewall log showing the scan traffic dropped by the default deny rule on WAN, timestamped to match the Nmap run above.

3. Brute-force — Hydra against the exposed SSH port

Hydra brute-force

Hydra dictionary attack against ssh://<WAN-IP>:2222 — a valid password is found.

4. Endpoint detection — Wazuh correlating the brute-force attempts

Wazuh correlated alert

Wazuh's Threat Hunting view shows a spike of sshd: authentication failed events, aggregated into a higher-severity Multiple authentication failures alert (rule 40111, level 10) — the SIEM correlating many low-level failures into one actionable event.

5. Post-exploitation (simulated)

Post-login actions

After recovering the password via brute-force, the attacker logs in over SSH and attempts a file-system action (touch on a file under a monitored path). In a real intrusion, this is the stage where an attacker would modify configuration, plant persistence, or access data on the host — and it is exactly the kind of activity Wazuh's File Integrity Monitoring (FIM) module is designed to catch, independently of whatever happened at the network layer.

6. Confirming the agent is alive and reporting

Wazuh agent active

Wazuh dashboard confirming the agent is active, with systemctl status wazuh-agent on the endpoint showing the agent process tree running.


What This Demonstrates

  • Layered defense: the same intrusion attempt produces distinct, complementary evidence at two different layers — the firewall sees and blocks reconnaissance traffic; the endpoint agent sees and correlates the authentication attack that got through the one open port.
  • Correlation over time: firewall log timestamps and Wazuh alert timestamps line up with the actual attack timeline (recon → block → brute-force → detection), without needing a single unified log pipeline (see Future Work).
  • Practical infrastructure troubleshooting: getting Wazuh Manager, Agent, and pfSense to talk to each other across bridged/NAT VirtualBox networking surfaced and resolved several real networking issues — documented in docs/wazuh.md.

Repository Structure

.
├── README.md
├── LICENSE
├── docs/
│   ├── pfsense.md                 # pfSense technical setup
│   ├── wazuh.md                   # Wazuh technical setup
│   └── screenshots/               # all screenshots referenced above
└── attack-simulation/
    └── passwords.txt              # wordlist used for the SSH brute-force demo

Future Work

  • Forward pfSense firewall logs to Wazuh via syslog for single-pane correlation instead of manual timestamp matching across two dashboards.
  • Deploy a deliberately vulnerable web app on the Ubuntu Agent to extend the scenario beyond SSH brute-force.

License

See LICENSE.


About

Home-lab SOC project demonstrating layered defense: a pfSense perimeter firewall and a Wazuh SIEM/XDR endpoint agent on separate VMs, with a simulated external attack (Nmap recon, Hydra SSH brute-force) correlated across both firewall logs and endpoint FIM/authentication alerts.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Contributors