Skip to content

About

LogiSecure SA — Enterprise Security Program Hub | CISO dashboard | 16-project cybersecurity portfolio

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

LogiSecure Enterprise Security Programme

ISO 27001 NIS2 MITRE ATT&CK CIS

Hub of my cybersecurity lab portfolio. Each project builds part of the security programme of LogiSecure SA, a fictional Belgian parcel logistics operator, on one shared lab environment. A project is listed here once its repository is published, plus the one in progress. Every figure on this page is evidenced in a repository.


LogiSecure SA — Fictional Enterprise Context

Attribute Detail
Sector Parcel logistics for B2B e-commerce — warehousing, automated sorting, collection and delivery
Size 500 employees · HQ Brussels, Belgium
NIS2 status Important entity under the Belgian NIS2 law (in force since 18 Oct 2024): courier service provider (Annex II — postal and courier services) · large enterprise · ex post supervision by the CCB
Reference frameworks ISO 27001 · IEC 62443 (OT)
OT environment Sorting conveyors · legacy HMI (Windows 7) · PLC · WMS · SCADA historian
Suppliers TechLogix BV (WMS) · ConveyorPro GmbH (OT) · DataAPI SAS (API)
Key risks Ransomware · IT→OT lateral movement · API data leak · Supply chain compromise

This table describes the scenario. What is actually built is shown in Lab Architecture.


Projects

Repository Status Evidenced results
logisecure-active-directory ✅ Completed AD domain lab.local with OU design · 4 GPOs (password, lockout, audit, hardening) · Wazuh agents on DC01 and WKS01 · 3 custom MITRE-mapped rules · PingCastle: Privileged Accounts 50 → 40, Stale Objects 41 → 36
logisecure-pfsense-segmentation ✅ Completed WAN / LAN / DMZ behind pfSense · 12 firewall rules, default-deny on every interface · Suricata on 3 interfaces (inline IPS on WAN, IDS on LAN and DMZ) · DMZ scan alerts in Wazuh, mapped to T1046 · OpenVAS validated against an nmap baseline
logisecure-ebios-rm-assessment 🔄 In progress EBIOS RM risk assessment of LogiSecure SA

Each completed project has a lessons_learned.md documenting what went wrong, why, and what changed — start with the detection rule that never fired for four months.


Lab Architecture

LOGISECURE SA — LAB AS BUILT

INTERNET / WAN (VirtualBox NAT)
    │
[pfSense CE 2.7.2 — firewall / router]          → logisecure-pfsense-segmentation
    │   Suricata: WAN inline IPS · LAN IDS · DMZ IDS
    │
    ├── [LAN IT — 10.10.10.0/24]
    │       DC01    10.10.10.10   AD DS · DNS · GPO    → logisecure-active-directory
    │       WKS01   10.10.10.20   domain workstation   → logisecure-active-directory
    │       Wazuh   10.10.10.30   SIEM manager         → logisecure-active-directory
    │
    └── [DMZ — 10.10.20.0/24]
            Kali    10.10.20.10   test / attack host   → logisecure-pfsense-segmentation

Detection paths: Wazuh agents on DC01 and WKS01 · DMZ Suricata alerts → syslog → Wazuh

Kali also runs OpenVAS (GVM); it was moved to the LAN (10.10.10.50) for the vulnerability scans, so that the scan measures the hosts rather than the firewall.

Known limits — documented in logisecure-pfsense-segmentation: the LAN is flat (no micro-segmentation); a gateway IDS cannot see traffic inside a segment, so lateral movement within 10.10.10.0/24 is only partly covered by the Wazuh agents; only the DMZ sensor is forwarded to Wazuh, over plain UDP syslog.


Security Posture — In Place and Known Gaps

Domain In place (evidenced) Known gaps Repository
Identity & Access Management 4 GPOs · MachineAccountQuota = 0 · AD Recycle Bin · AES256 on all accounts · NTLMv2 only · LDAP signing · admin account marked sensitive · PingCastle Privileged Accounts 50 → 40, Stale Objects 41 → 36 PingCastle domain risk level still 55/100 — residual Anomalies (pass-the-credential, network sniffing) logisecure-active-directory
Network Segmentation LAN and DMZ behind pfSense · 12 justified rules, default-deny on every interface · DMZ→LAN blocked and logged · 7 logged rules LAN still flat · rules 2, 3 and 10 in place but untested — they govern access to a DMZ web service not deployed yet logisecure-pfsense-segmentation
Threat Detection Wazuh 4.14.5 · 2 agents · DMZ Suricata alerts parsed by a custom decoder · 3 custom AD rules mapped to T1078, T1087 and T1110 · network scans detected and mapped to T1046, validated with nmap from the DMZ The T1110 rule (100001) fires on a single failed logon — it detects failures, not brute force yet · rule 100002 is noisy · WAN and LAN sensors not forwarded logisecure-active-directory · logisecure-pfsense-segmentation
Vulnerability Management OpenVAS unauthenticated scan of DC01 and WKS01, first scan invalidated by an nmap baseline and redone: 0 Critical · 0 High · 2 Medium · 1 Low No authenticated (patch-level) scan yet · 2 NVTs timed out on DC01 logisecure-pfsense-segmentation

Frameworks Applied

Framework Where it is applied
MITRE ATT&CK Detections mapped to T1046 (Suricata scan alerts in Wazuh), T1078 and T1087 (custom Wazuh rules) · Mitigations for T1110 (account lockout) and T1557 (LLMNR disabled)
CIS Benchmarks GPO hardening — password and lockout policies, NTLMv2 only, SMB signing
ISO 27001:2022 · NIS2 Art. 21 Default-deny firewall rules justified against ISO 27001 A.8.20 and NIS2 Art. 21

All environments simulate the fictional enterprise LogiSecure SA, used solely for educational and portfolio purposes.

Built by Maxime Belliard — Cybersecurity · Technical & GRC

About

LogiSecure SA — Enterprise Security Program Hub | CISO dashboard | 16-project cybersecurity portfolio

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors