Bonus – Adding Mordor Datasets to our ELK instance
For those that cannot set up an ESXI environment or for those that just want to practice their hunting skills over a set of logs result of an APT emulation plan without having to carry out the emulation themselves, there is an excellent alternative.
We have already talk about the Mordor project in the past chapter, but just to refresh your memories, Mordor is a project also carried out by the brothers Roberto and Jose Rodriguez. Their project provides “free portable datasets to expedite the development of analytics”.
You can download the datasets from Mordor-lab GitHub. For this example, I’m going to use APT29 ATT&CK evaluations dataset that you can download from the following link: https://github.com/OTRF/detection-hackathon-apt29/tree/master/datasets.
For those that use The HELK, there is a guide with a YouTube video on how to import the dataset to the environment using Kafkacat: https://mordordatasets...