Deployment Proposal
Proposed architecture for the Dragonscale Defense home SOC lab · 7 min read
Objective
The goal is to build a segmented Azure virtual network for hands-on Active directory training, analyzing traffic and creating detection rules with Microsoft sentinel, simulating and responding to kali Linux attacks. This Lab will provide Windows and Linux clients and servers to simulate a real enterprise network. These machines will have bash scripts that simulate user activity for log creation and ingestion. In addition to the logs created by security incidents. The lab will contain a Vnets with multiple subnets and security groups implementing the principles of least privilege. Following the idea of least privilege all admin access will be through azure bastion.
The learning objective are to defend and configure:
- Microsoft sentinel
- Active directory
- Azure infrastructure
- Windows and Linux machines
Architecture Overview
Following the goal of the project, 4 subnets will be created; Sub_server to host the AD controller and Wazuh, Sub_client with user sim scripts to generate logs, Sub_attack the location of the attack VM, and AzureBastionSubnet where all administrative actions will take place. Following the design principle of least privilege all Network Security Groups will be set to only allow azure bastion, only the services used as they are created/needed. Log collection will be through wazuh and AD. These will all be forward to Microsoft sentinel for analysis and actions.
Asset Inventory
| # | Asset Name | Asset type | Function/Purpose | IP/CIDR | Location |
|---|---|---|---|---|---|
| 1 | Public IP address | Network | Connection to the internet and hub | unknown | North Europe |
| 2 | VNet | Network | Network hub | 10.50.0.0/16 | North Europe |
| 3 | Sub_server | Subnet | Segmentation, role control | 10.50.1.0/24 | North Europe |
| 4 | Sub_client | Subnet | Segmentation, role control | 10.50.2.0/24 | North Europe |
| 5 | Sub_attack | Subnet | Segmentation, role control | 10.50.3.0/24 | North Europe |
| 6 | AzureBastionSubnet | Subnet | Segmentation, role control, administration | 10.50.4.0/26 | North Europe |
| 7 | NSG_server | NSG | Network Traffic control | North Europe | |
| 8 | NSG_client | NSG | Network Traffic control | North Europe |
|
| 9 | NSG_attack | NSG | Network Traffic control | North Europe |
|
| 10 | NSG_bastion | NSG | Network Traffic control | North Europe |
|
| 11 | Linux_client | VM | Simulated employees running activity scripts, log generation | 10.50.2.10 | North Europe |
| 12 | Windows_client | VM | Simulated employees running activity scripts, log generation | 10.50.2.20 | North Europe |
| 13 | Linux_server | VM | Wazuh host | 10.50.1.10 | North Europe |
| 14 | Windows_server | VM | AD domain controller, log generation | 10.50.1.11 | North Europe |
| 15 | Kali_attack | VM | Attack machine | 10.50.3.10 | North Europe |
| 16 | Sentinel | SIEM instance | Detection rules, analytics and incidents | ||
| 17 | Wazuh | EDR Software | endpoint log collection | ||
| 18 | Log Analytics workspace | PaaS | a monitoring/data service | North Europe |
Network Diagram

Phased Plan
| Phase | Scope | Deliverable | Success criteria |
|---|---|---|---|
| 1. Network | VNet, 4 subnets, NSG, Bastion, LAW | bicep template for network 01-network.bicep | Network deployment succeeds, NSG tests and connectivity test pass. |
| 2. AD | Active directory (Still learning exactly what this implies, evolving ) | Policy doc, AD deployment doc, and bicep template, user sim script | Successfully deploy active directory, running test on each part, |
| 3. Sentinal | Enabling sentinel, forwarding all logs, creating rules and detections | Sentinel configuration Doc, Rules Doc, bicep template, server sim script | Events visible in Microsoft sentinel, and 3 security rules created and active |
| 4. Attack | kali config, attacking clients and or server and mapping the attack to mitter. | bicep template, attack write up and mapping doc | Successfully created attack logs(signatures) |
| 5. Dettections | write detection rules for the attack done | Detection rule doc | Successfully created detection rules and automated responses |
| 6. Hardening | hardening clients and servers against simulated attacks | Hardening Repot, and updated NSD | Rerun attack and clients, servers, and network was not vulnerable |
Cost & Lifecycle
Cost Breakdown by Component
When calculating the estimated cost we made the assumption that all the recourses will be running for a total of 10 to 20 hours a month in North Europe totaling to $11.52 to $15.30 of incurred cost a month.
| Service category | Service type | Custom name | Region | Description | Min (10 hrs/mo) | Max (20 hrs/mo) |
|---|---|---|---|---|---|---|
| Networking | IP Addresses | — | North Europe | Basic (Classic), 0 Dynamic IP × 730 Hrs, 1 Static IP Address | $0.04 | $0.07 |
| Networking | Azure Bastion | — | North Europe | Basic Tier, 5 GB Outbound Data Transfer | $1.90 | $3.80 |
| Compute | Virtual Machines | Linux VMs | North Europe | 3 × A1 v2 (1 Core, 2 GB RAM), Pay-as-you-go, Linux; 5 GB outbound inter-region transfer | $1.23 | $2.46 |
| Security | Microsoft Sentinel | — | North Europe | Free tier — 0 GB/day Analytics + Data Lake; 3 months retention; 0 compute units | $0.00 | $0.00 |
| Compute | Virtual Machines | Windows VMs | North Europe | 1 × A1 v2 (1 Core, 2 GB RAM), Pay-as-you-go, Windows (license included); 5 GB outbound inter-region | $0.62 | $1.24 |
| Storage | Managed Disks | — | North Europe | Standard HDD, S4 Disk Type, 5 Disks, 100 Storage transactions — bills 24/7 regardless of VM uptime | $7.73 | $7.73 |
| Support | — | — | — | Licensing Program: Microsoft Customer Agreement (MCA) | $0.00 | $0.00 |
| Total Monthly | $11.52 | $15.30 |
Cost Optimization Strategy
To optimize costs incurred by the SOC lab, we will Implement:
- Auto-shutdown of VMs when not in use
- Log retentions will be set at 5 days
- Cost alerts and threshold alerts
Lifecycle Phases
- Build Architecture (1 Month)
- Deploy VMs
- Deploy network
- Active Directory
- Sentinel and log Analytics free tier
- Operations (1 Month)
- Run attack simulations
- Ingest telemetry
- Tune detection rules
- Evaluation and reporting (2 Weeks)
- analyze detections
- Document operations and detections
- Documentation / Archive (2 days)
- Tear down everything (all resources in inventory )
- Take images of vms
- Save Deployment templates
Total Projected Cost
Following a 2 and a half month lifecycle, and the monthly component cost above, the total projected cost of $28.80-$39.27.
| Lifecycle phase | Duration | Est. spend |
|---|---|---|
| Build | 1 month | ~$11.52-$15.30 |
| Operations | 1 month | ~$11.52-$15.30 |
| Evaluation | 2 weeks | ~$5.76-$7.65 |
| Teardown / Archive | 2 days | ~$0.77-$1.02 |
| Total | ~$28.80-$39.27 |
Risk and Assumptions
| Risk | Impact | Likelihood | Mitigation |
|---|---|---|---|
| VM size unavailable in North Europe region | Deployment failure, | low | Failover zone (west germany) |
| NSG rules block legitimate traffic (false positive lockdown) | loss of connectivity | medium | Test NSG rules Incrementally, and keep bastion path open |
| Kali VM accidentally exposed to public internet | Security incident, incresed attack surface | low | Verify that NSG denies all inbound connections except bastion |
| Auto-shutdown fails or schedules misconfigured | Unexpected incurred costs | low | Set multiple reminder alerts, set up test to verify VMs is deallocated, deallocate manually |
| Learning curve extends timeline (AD/Sentinel complexity) | Project delyed beyond 2.5 months | medium | Build buffers, test implimintations locally before deployment, create the minimum working detection rules. |
| Assumption | Verification Method |
|---|---|
| Student subscription with 50$ of credit available | Confirm via Azure portal |
| Wazuh can forward logs to Microsoft sentinel | Test with single log source before full deployment |
| Azure basic is sufficient for remote management | Review features, validate bastions work after phase 1 |
| North Europe supports all services required | Check service availability in azure documentation |
Next Steps
With the architecture, phased plan, cost model, and risks documented, the project is ready to start phase 1.
| Priority | Action | Gate to pass |
|---|---|---|
| 1 | Verify Azure subscription credit, budget alerts, and service availability in North Europe | Budget alert fires at $20 spend |
| 2 | Deploy 01-network.bicep and validate |
All subnets reachable via Bastion; NSG default-deny confirmed by test |
| 3 | Begin Phase 2 (Active Directory) | Both clients domain-joined |