Security operations lab · Completed

Monitor.

A Windows environment built to turn system activity into evidence that can be investigated and explained.

The lab uses Windows Server 2025 Standard Evaluation with Desktop Experience in VirtualBox. Each monitoring claim is supported by configuration records, event data, investigation notes, and repeatable validation.

TYPESecurity operations lab

PLATFORMWindows Server 2025 · VirtualBox

FOCUSAdministration · telemetry · response

DELIVERYEvidence · notes · repository documentation

01 · The goal

Show how Windows activity becomes an investigation timeline.

Security monitoring is more than opening Event Viewer. The lab connects Windows administration, identity, endpoint behavior, event collection, PowerShell analysis, and incident documentation into one supportable workflow.

Selected actions were generated intentionally. The resulting records were filtered, correlated, explained, and preserved to demonstrate both technical configuration and analytical reasoning.

02 · Lab environment

Generate activity. Centralize evidence. Investigate the result.

The environment stays small enough to rebuild and understand while still producing realistic identity, endpoint, service, and policy events.

WINDOWS SYSTEMS

Server and endpoint

Windows Server 2025, a connected client, identity services, administrative tasks, and controlled test activity.

EVENT VISIBILITY

Collect and filter

Relevant Windows logs, centralized event access, saved queries, and PowerShell based retrieval.

INVESTIGATION

Explain and verify

Timeline reconstruction, evidence notes, remediation, recovery, and a final validation check.

03 · Build scope

The monitoring workflow is repeatable.

Each stage produces an observable result and a written procedure instead of an undocumented single setup.

01

Windows Server foundation

Built and documented the Windows Server 2025 Standard Evaluation virtual machine, networking, updates, snapshots, and recovery checkpoints.

02

Identity and name services

Added a small Windows domain and supporting DNS so authentication and administrative activity produced realistic security events.

03

Endpoint telemetry

Connected a Windows client and identified the local and forwarded logs needed to trace sign ins, account changes, process activity, and policy events.

04

Central event visibility

Collected relevant Windows events in one place, applied useful filtering, and separated normal administrative activity from behavior worth investigating.

05

PowerShell investigation

Used repeatable PowerShell queries to retrieve, filter, correlate, and export event evidence instead of relying only on manual Event Viewer navigation.

06

Controlled test activity

Generated safe authentication, account, service, and policy changes so the monitoring workflow could be tested against known actions.

07

Incident notes

Documented the trigger, timeline, evidence, interpretation, remediation, and verification for each selected scenario.

08

Recovery and validation

Used snapshots and written recovery steps to confirm that the lab could be restored and that monitoring still worked after changes.

04 · Validation workflow

Build, observe, investigate, document.

The project records each verified milestone, from the server baseline through event collection, investigation, remediation, and recovery.

  1. 01

    Establish the lab

    Installed Windows Server 2025 Standard Evaluation with Desktop Experience in VirtualBox and documented the baseline configuration.

  2. 02

    Create useful telemetry

    Added the Windows services, client activity, event collection, and PowerShell queries needed for repeatable investigation.

  3. 03

    Generate and investigate

    Performed controlled administrative and security related actions, then reconstructed what happened from the collected evidence.

  4. 04

    Document the evidence

    Added sanitized screenshots, event queries, timelines, incident notes, recovery steps, and repository documentation.

Verified evidence

The page shows what happened and how it was proven.

Evidence includes sanitized configuration notes, Windows event queries, screenshots, timelines, controlled scenario records, investigation findings, remediation steps, recovery validation, and repository documentation.

  • Windows Server 2025
  • VirtualBox
  • Windows administration
  • Event logs
  • PowerShell
  • Identity
  • Investigation
  • Incident documentation
Validation summary

The Windows environment was configured, connected, exercised with controlled activity, investigated through event evidence, restored from snapshots, and verified after recovery.

The larger takeaway

I use system evidence to turn unclear activity into a documented answer.

Discuss the work View résuméView all selected work