clong / DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices
MIT License
4.64k stars 987 forks source link

Swap Splunk for Invoke-IR ACE and Helk #43

Closed 1332530 closed 6 years ago

1332530 commented 6 years ago

This is not really an issue, but perhaps a direction that would be interessting, for users, but also for the respective devs of the 2 projects.

Alot of props for powershell based DFIR, and the HELK project contains very modular sysmon configs, a Spark analytics layer, and an integration with Invoke-IR ACE.

I feel kinda cheap raising this without actually offering to help out, but my devs skills aren't tip top =/

clong commented 6 years ago

Hi @1332530,

It's an interesting idea! That would require quite an overhaul of DetectionLab, and would probably belong on its own fork as I don't think it makes sense to actually replace Splunk in this project.