sandeepmothukuri/Enterprise-Detection-Engineering-SOC-Lab ? reverse-engineered prompt

Reverse engineered prompt

Build me a complete hands on SOC lab that I can run on one machine with Docker Compose.

I want it to feel like a real security operations center, with a simple portal, live dashboards, alert feeds, threat hunting views, case management, and a way to simulate attacks so I can test the detections. It should include OpenSearch for search and dashboards, Zeek and Suricata for network monitoring, MISP for threat intel, Velociraptor for live forensics, Caldera for adversary emulation, and some basic SOAR style response workflows. Add a few AI helpers that can look at alerts, help with triage, and suggest hunts or detection ideas.

Please make the setup easy, with a single install flow, health checks, example configs, and clear docs for getting it running on Linux, WSL2, or macOS. If you need current setup details or best practices, look them up online. I want the whole thing to work as a polished learning lab, not just a pile of containers.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab