SOC-lab-tools offers a set of tools for Windows systems, designed specifically for Security Operations Centers (SOC) and controlled test environments. This software automates the setup of TLS key logging for encrypted web traffic analysis. It also allows you to enable or disable 16 Windows Defender components, helping with malware research, detection engineering, and Blue Team training.
To get started with SOC-lab-tools, follow these steps:
Visit the Releases Page
Go to our Releases page to find the latest version.
Download the Application
Look for the latest release, and click on the installation file to download it. This file might be named something like SOC-lab-tools-installer.exe.
Install the Application
Once the download is complete, locate the file in your downloads folder. Double-click the installer to start the setup process. Follow the on-screen instructions.
Launch the Application
After installation, find the SOC-lab-tools icon on your desktop or in your Start menu. Click to open the application.
Ensure your system meets these requirements for optimal performance.
Enabling TLS Key Logging
When you launch the SOC-lab-tools, look for the TLS key logging feature. Click on it to enable logging of encrypted web traffic automatically.
Managing Windows Defender
Navigate to the Windows Defender management section in the app. Choose which components or drivers you want to enable or disable by selecting from a list. Click “Apply Changes” to update settings.
Analysis Tools
After setting up TLS key logging, use the built-in tools to start analyzing data. The application will guide you through the process.
If you encounter issues while using SOC-lab-tools:
Installation Problems: Ensure that your Windows version is compatible. Run the installer as an Administrator if you face permission issues.
Application Crashes: Make sure you have the latest version. Check for updates on the Releases page.
Key Logging Issues: Ensure you have the required permissions to capture traffic. Restart the application if needed.
Documentation
Access the user manual and additional guides for more details on using specific features.
Community Support
Visit the issues section on GitHub to report problems or ask questions. The community and developers are here to help.
We welcome your input on SOC-lab-tools. If you have suggestions or encounter issues, please open an issue on our GitHub page.
Thank you for using SOC-lab-tools! Your work in improving security operations is vital. Enjoy using our software.