SOC analyst home lab built on ELK Stack — SSH/RDP brute force detection, Mythic C2 attack simulation, Apollo agent hunting, Elastic Defend EDR, and osTicket alert-to-ticket pipeline.
-
Updated
Jun 7, 2026
SOC analyst home lab built on ELK Stack — SSH/RDP brute force detection, Mythic C2 attack simulation, Apollo agent hunting, Elastic Defend EDR, and osTicket alert-to-ticket pipeline.
Automated Elastic Security SIEM/EDR infrastructure with TLS, Fleet orchestration, endpoint telemetry, ATT&CK-aligned detection, and Zeek integration. Website
Lab 2 for Cyber Threat Intelligence (CTI) — Integration of MISP with Elastic Stack for IoC ingestion, and deployment of Elastic Agents on Linux and Windows endpoints via Fleet Server for centralized log forwarding.
To associate your repository with the fleet-server topic, visit your repo's landing page and select "manage topics."