Aleksander9191/Elastic-Detection-Lab

GitHub: Aleksander9191/Elastic-Detection-Lab

基于 Elastic Security、Sysmon 和 Atomic Red Team 构建的检测工程实验室,用于开发、验证和记录针对 MITRE ATT&CK 技术的检测规则。

Stars: 0 | Forks: 0

# Elastic Detection Lab 基于 **Elastic Security**、**Sysmon** 和 **Atomic Red Team** 构建的 Detection Engineering 作品集。 本仓库的目标是模拟 MITRE ATT&CK 技术,调查收集到的遥测数据,评估内置的 Elastic 检测,并开发自定义检测规则。 ## 实验环境架构 | 组件 | 技术 | |-----------|------------| | SIEM | Elastic Security 9.4 | | Endpoint 遥测 | Sysmon | | Agent | Elastic Agent | | 攻击模拟 | Atomic Red Team | | 框架 | MITRE ATT&CK | ## 方法论 每项技术都遵循相同的工作流程: 1. 执行 Atomic Red Team 模拟 2. 在 Elastic Discover 中分析收集到的遥测数据 3. 验证现有的 Elastic 检测规则 4. 开发自定义检测规则(如有需要) 5. 验证告警生成 6. 记录发现 ## 已完成技术 | 技术 | 状态 | |-----------|--------| | T1087.001 – Local Account Discovery | ✅ | | T1059.001 – PowerShell | 🚧 | ## 技术 - Elastic Security - Elastic Agent - Sysmon - Atomic Red Team - MITRE ATT&CK - Detection Engineering - Threat Hunting ## 未来工作 - 更多 MITRE ATT&CK 技术 - EQL 序列规则 - Sigma 规则等价物 - ECS 标准化 - 调查指南 - 检测调优 - 误报分析
标签:Atomic Red Team, Cloudflare, Elastic Security, MITRE ATT&CK, OpenCanary, Sysmon, 数据泄露检测