Deployment Proposal

Proposed architecture for the Dragonscale Defense home SOC lab · 7 min read

Objective

The goal is to build a segmented Azure virtual network for hands-on Active directory training, analyzing traffic and creating detection rules with Microsoft sentinel, simulating and responding to kali Linux attacks. This Lab will provide Windows and Linux clients and servers to simulate a real enterprise network. These machines will have bash scripts that simulate user activity for log creation and ingestion. In addition to the logs created by security incidents. The lab will contain a Vnets with multiple subnets and security groups implementing the principles of least privilege. Following the idea of least privilege all admin access will be through azure bastion.

The learning objective are to defend and configure:

Architecture Overview

Following the goal of the project, 4 subnets will be created; Sub_server to host the AD controller and Wazuh, Sub_client with user sim scripts to generate logs, Sub_attack the location of the attack VM, and AzureBastionSubnet where all administrative actions will take place. Following the design principle of least privilege all Network Security Groups will be set to only allow azure bastion, only the services used as they are created/needed. Log collection will be through wazuh and AD. These will all be forward to Microsoft sentinel for analysis and actions.

Asset Inventory

# Asset Name Asset type Function/Purpose IP/CIDR Location
1 Public IP address Network Connection to the internet and hub unknown North Europe
2 VNet Network Network hub 10.50.0.0/16 North Europe
3 Sub_server Subnet Segmentation, role control 10.50.1.0/24 North Europe
4 Sub_client Subnet Segmentation, role control 10.50.2.0/24 North Europe
5 Sub_attack Subnet Segmentation, role control 10.50.3.0/24 North Europe
6 AzureBastionSubnet Subnet Segmentation, role control, administration 10.50.4.0/26 North Europe
7 NSG_server NSG Network Traffic control   North Europe
8 NSG_client NSG Network Traffic control   North Europe
9 NSG_attack NSG Network Traffic control   North Europe
10 NSG_bastion NSG Network Traffic control   North Europe
11 Linux_client VM Simulated employees running activity scripts, log generation 10.50.2.10 North Europe
12 Windows_client VM Simulated employees running activity scripts, log generation 10.50.2.20 North Europe
13 Linux_server VM Wazuh host 10.50.1.10 North Europe
14 Windows_server VM AD domain controller, log generation 10.50.1.11 North Europe
15 Kali_attack VM Attack machine 10.50.3.10 North Europe
16 Sentinel SIEM instance Detection rules, analytics and incidents    
17 Wazuh EDR Software endpoint log collection    
18 Log Analytics workspace PaaS a monitoring/data service   North Europe

Network Diagram

DragonScale Soc Lab Network Diagram

Phased Plan

Phase Scope Deliverable Success criteria
1. Network VNet, 4 subnets, NSG, Bastion, LAW bicep template for network 01-network.bicep Network deployment succeeds, NSG tests and connectivity test pass.
2. AD Active directory (Still learning exactly what this implies, evolving ) Policy doc, AD deployment doc, and bicep template, user sim script Successfully deploy active directory, running test on each part,
3. Sentinal Enabling sentinel, forwarding all logs, creating rules and detections Sentinel configuration Doc, Rules Doc, bicep template, server sim script Events visible in Microsoft sentinel, and 3 security rules created and active
4. Attack kali config, attacking clients and or server and mapping the attack to mitter. bicep template, attack write up and mapping doc Successfully created attack logs(signatures)
5. Dettections write detection rules for the attack done Detection rule doc Successfully created detection rules and automated responses
6. Hardening hardening clients and servers against simulated attacks Hardening Repot, and updated NSD Rerun attack and clients, servers, and network was not vulnerable

Cost & Lifecycle

Cost Breakdown by Component

When calculating the estimated cost we made the assumption that all the recourses will be running for a total of 10 to 20 hours a month in North Europe totaling to $11.52 to $15.30 of incurred cost a month.

Service category Service type Custom name Region Description Min (10 hrs/mo) Max (20 hrs/mo)
Networking IP Addresses — North Europe Basic (Classic), 0 Dynamic IP × 730 Hrs, 1 Static IP Address $0.04 $0.07
Networking Azure Bastion — North Europe Basic Tier, 5 GB Outbound Data Transfer $1.90 $3.80
Compute Virtual Machines Linux VMs North Europe 3 × A1 v2 (1 Core, 2 GB RAM), Pay-as-you-go, Linux; 5 GB outbound inter-region transfer $1.23 $2.46
Security Microsoft Sentinel — North Europe Free tier — 0 GB/day Analytics + Data Lake; 3 months retention; 0 compute units $0.00 $0.00
Compute Virtual Machines Windows VMs North Europe 1 × A1 v2 (1 Core, 2 GB RAM), Pay-as-you-go, Windows (license included); 5 GB outbound inter-region $0.62 $1.24
Storage Managed Disks — North Europe Standard HDD, S4 Disk Type, 5 Disks, 100 Storage transactions — bills 24/7 regardless of VM uptime $7.73 $7.73
Support — — — Licensing Program: Microsoft Customer Agreement (MCA) $0.00 $0.00
Total Monthly         $11.52 $15.30

Cost Optimization Strategy

To optimize costs incurred by the SOC lab, we will Implement:

Lifecycle Phases

  1. Build Architecture (1 Month)
    • Deploy VMs
    • Deploy network
    • Active Directory
    • Sentinel and log Analytics free tier
  2. Operations (1 Month)
    • Run attack simulations
    • Ingest telemetry
    • Tune detection rules
  3. Evaluation and reporting (2 Weeks)
    • analyze detections
    • Document operations and detections
  4. Documentation / Archive (2 days)
    • Tear down everything (all resources in inventory )
    • Take images of vms
    • Save Deployment templates

Total Projected Cost

Following a 2 and a half month lifecycle, and the monthly component cost above, the total projected cost of $28.80-$39.27.

Lifecycle phase Duration Est. spend
Build 1 month ~$11.52-$15.30
Operations 1 month ~$11.52-$15.30
Evaluation 2 weeks ~$5.76-$7.65
Teardown / Archive 2 days ~$0.77-$1.02
Total   ~$28.80-$39.27

Risk and Assumptions

Risk Impact Likelihood Mitigation
VM size unavailable in North Europe region Deployment failure, low Failover zone (west germany)
NSG rules block legitimate traffic (false positive lockdown) loss of connectivity medium Test NSG rules Incrementally, and keep bastion path open
Kali VM accidentally exposed to public internet Security incident, incresed attack surface low Verify that NSG denies all inbound connections except bastion
Auto-shutdown fails or schedules misconfigured Unexpected incurred costs low Set multiple reminder alerts, set up test to verify VMs is deallocated, deallocate manually
Learning curve extends timeline (AD/Sentinel complexity) Project delyed beyond 2.5 months medium Build buffers, test implimintations locally before deployment, create the minimum working detection rules.
Assumption Verification Method
Student subscription with 50$ of credit available Confirm via Azure portal
Wazuh can forward logs to Microsoft sentinel Test with single log source before full deployment
Azure basic is sufficient for remote management Review features, validate bastions work after phase 1
North Europe supports all services required Check service availability in azure documentation

Next Steps

With the architecture, phased plan, cost model, and risks documented, the project is ready to start phase 1.

Priority Action Gate to pass
1 Verify Azure subscription credit, budget alerts, and service availability in North Europe Budget alert fires at $20 spend
2 Deploy 01-network.bicep and validate All subnets reachable via Bastion; NSG default-deny confirmed by test
3 Begin Phase 2 (Active Directory) Both clients domain-joined