Aleksander9191/Elastic-Detection-Lab
GitHub: Aleksander9191/Elastic-Detection-Lab
基于 Elastic Security、Sysmon 和 Atomic Red Team 构建的检测工程实验室,用于开发、验证和记录针对 MITRE ATT&CK 技术的检测规则。
Stars: 0 | Forks: 0
# Elastic Detection Lab
基于 **Elastic Security**、**Sysmon** 和 **Atomic Red Team** 构建的 Detection Engineering 作品集。
本仓库的目标是模拟 MITRE ATT&CK 技术,调查收集到的遥测数据,评估内置的 Elastic 检测,并开发自定义检测规则。
## 实验环境架构
| 组件 | 技术 |
|-----------|------------|
| SIEM | Elastic Security 9.4 |
| Endpoint 遥测 | Sysmon |
| Agent | Elastic Agent |
| 攻击模拟 | Atomic Red Team |
| 框架 | MITRE ATT&CK |
## 方法论
每项技术都遵循相同的工作流程:
1. 执行 Atomic Red Team 模拟
2. 在 Elastic Discover 中分析收集到的遥测数据
3. 验证现有的 Elastic 检测规则
4. 开发自定义检测规则(如有需要)
5. 验证告警生成
6. 记录发现
## 已完成技术
| 技术 | 状态 |
|-----------|--------|
| T1087.001 – Local Account Discovery | ✅ |
| T1059.001 – PowerShell | 🚧 |
## 技术
- Elastic Security
- Elastic Agent
- Sysmon
- Atomic Red Team
- MITRE ATT&CK
- Detection Engineering
- Threat Hunting
## 未来工作
- 更多 MITRE ATT&CK 技术
- EQL 序列规则
- Sigma 规则等价物
- ECS 标准化
- 调查指南
- 检测调优
- 误报分析
标签:Atomic Red Team, Cloudflare, Elastic Security, MITRE ATT&CK, OpenCanary, Sysmon, 数据泄露检测