Summary
In this chapter we have learned how to set up our research environment. We learnt how to set up a VMware ESXI environment, prepare a Windows Server with Active Directory, configure the server clients, fill our server with fake users and establishing our audit policy. We have also learned how to run and configure Sysmon and how to send the logged information to our ELK or HELK instance.
In the next chapter we are going to learn how to query all the information we are gathering, i.e., we are going to learn how to carry out our first hunts!