Bonus – adding Mordor datasets to our ELK instance
For those that cannot set up an ESXI environment, or for those that just want to practice their hunting skills over a set of log results from an APT emulation plan without having to carry out the emulation themselves, there is an excellent alternative.
We talked about the Mordor project in the previous chapter, but just to refresh your memory, Mordor is a project that's also carried out by the brothers Roberto and Jose Rodriguez. Their project provides "free portable datasets to expedite the development of analytics."
You can download the datasets from the Mordor-lab GitHub. Throughout this book, I'm going to use the APT29 ATT&CK evaluations dataset, which you can download from the following link: https://github.com/OTRF/detection-hackathon-apt29/tree/master/datasets.
For those that use the HELK, there is a YouTube video guide on how to import the dataset into the environment using Kafkacat:...