7.
Creating a research environment
In this chapter we are going learn how to set up a research environment to simulate threats and carry out the hunts. We are going to start for simulating an organizational environment with Windows Server and Windows 10, establishing a logging policy and centralizing the data in an Elasticsearch environment. Finally, we are going to close the chapter reviewing some of the other options we have to save us some of the trouble of building everything from scratch.
In this chapter we’re going to cover the following main topics:
- Setting up a research environment
- Installing VMware ESXI
- Installing Windows Server
- Configuring Windows Server
- Setting up ELK
- Configuring Winlogbeat
- Bonus – Adding Mordor datasets to our ELK instance
- The HELK an Open Source Tool by Roberto Rodriguez