Additional resources
In this chapter, we demonstrated how to build a detection lab from scratch using the Elastic Stack, Fleet, and Windows hosts, which will allow you to customize it to your needs as well as better understand the underlying technology concepts. However, many open source projects have attempted to provide simplified deployments of entire lab infrastructure, as well as other log aggregation technologies outside of the Elastic Stack. The following list provides some projects to look into if you want to explore other options. The rest of this book’s labs will add to this chapter’s lab, though:
- DetectionLab (https://detectionlab.network/, no longer maintained)
- The Hunting ELK (https://thehelk.com/intro.html)
- Matano (https://github.com/matanolabs/matano)
- Wazuh (https://wazuh.com/)
You can use these projects if you want to automate parts of deploying a DE environment.