Use Case Factory Testing Lab is an internal tool built for the Airbus Security Operations Center (SOC) to validate and continuously test cyber-attack detection use cases. It allows SOC analysts to select real-world attack scenarios, execute them on controlled test machines, and verify whether existing detection rules still trigger correctly in Splunk. I led the product and technical design and developed the frontend.
Key features:
- ๐งช Attack selection & execution: Choose specific cyber-attack scenarios to test SOC detection rules
- ๐ Monitoring dashboard: Track pending and running tests, re-run or skip executions, and download PDF reports
- ๐ค Automated execution: Automatically run supported attacks on dedicated test machines and monitor their detection
- ๐งญ Manual execution flows: Step-by-step guidance for attacks requiring human interaction
- ๐ Reporting: Generate PDF reports summarizing detection success and coverage
- ๐ก๏ธ MITRE ATT&CK mapping: Test and validate detection rules against standardized attack techniques
โ
Period
Sep 2020
-
And Ongoing
Mar 2021
type
Web App, Cybersecurity, Security Operations Center
Tech used
Typescript, React, MUI, Redux, Go