To get the most out of this book
Although alternatives for those that can't build their own server are provided in Chapter 7, Creating a Research Environment, to get the most out of this book, you will need your own server with VMware EXSI.
The minimum server requirements are as follows:
- 4–6 cores
- 16–32 GB RAM
- 50 GB - 1 TB of storage space
Nevertheless, you could still go through almost all the exercises of the book with an ELK/HELK instance and Mordor datasets. Other Splunk alternatives are also referenced in Chapter 7, Creating a Research Environment.
You will carry out advanced hunting using MITRE ATT&CK Evals emulations using Mordor datasets.
Being familiar with the MITRE ATT&CK Enterprise matrix would be a great advantage while using the book.
If you are using the digital version of this book, we advise you to type the code yourself. Doing so will help you avoid any potential errors related to the copying and pasting of code.
All links presented in the book go to a bit.ly
URL in order to analyze and better understand the usage of the book. This is not being monetized in any way and if you would prefer not to be part of the statistics, please copy and paste the provided URLs.