SOC analyst home lab built on ELK Stack — SSH/RDP brute force detection, Mythic C2 attack simulation, Apollo agent hunting, Elastic Defend EDR, and osTicket alert-to-ticket pipeline.
-
Updated
Jun 7, 2026
SOC analyst home lab built on ELK Stack — SSH/RDP brute force detection, Mythic C2 attack simulation, Apollo agent hunting, Elastic Defend EDR, and osTicket alert-to-ticket pipeline.
Lab 2 for Cyber Threat Intelligence (CTI) — Integration of MISP with Elastic Stack for IoC ingestion, and deployment of Elastic Agents on Linux and Windows endpoints via Fleet Server for centralized log forwarding.
Add a description, image, and links to the fleet-server topic page so that developers can more easily learn about it.
To associate your repository with the fleet-server topic, visit your repo's landing page and select "manage topics."