Detection Engineering Lab: Elastic SIEM vs Cobalt Strike
Deploy a compact Elastic Stack, ingest Sysmon telemetry, simulate a Cobalt Strike beacon, and harden detections with ATT&CK-aligned analytics and Sigma automation.
FIRST OBJECTIVES
- Deploy Elastic Stack with index lifecycle management tuned for home hardware
- Enable Sysmon operational logging with minimal performance footprint
- Simulate Cobalt Strike beacon activity mapped to ATT&CK T1059 and T1105

