Open juju4 opened 1 year ago
Elasticseach has few integrations for sysmon linux and osquery but using elastic agent instead of beat. may want or not use it https://docs.elastic.co/integrations/sysmon_linux https://docs.elastic.co/integrations/osquery https://www.elastic.co/guide/en/fleet/current/beats-agent-comparison.html#additional-capabilities-beats-and-agent else filebeat has module for osquery https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-osquery.html https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html
grafana dashboards for logs system, volume, licensing, error/warn: cribl, splunk, so
anticipate more / test early full environment load on logging and probably other aspects
From sans-ab email thread
on web side (vulnerable webserver, wiki...), need to generate some normal+noise traffic on webserver else not really real word. same with AutoHotKeys to do noise on Windows end-users
Background:
ideas list. requirements/outcomes to be determined by BTV.
Features/Capabilities
Infra