Summary
In this chapter, we built out the lab infrastructure that will be leveraged in the rest of the lab exercises within this book. We did this by leveraging Docker to deploy containers. Our lab includes the Elastic Stack, Fleet Server, and a single Windows host.
In Chapter 4, we will dive into the data sources we can use to build detection, such as application or endpoint logs. We’ll discuss how to identify valuable data sources and add those data sources to the lab.