The data
In the last post we set a platform to store the data. Now we need to feed it with some data. One way would be to install Windows virtual machines, Winlogbeat and Sysmon, but we will do that later. Now I want to talk about Mordor.
Mordor
This project, also maintained by Roberto Rodríguez and José Luis Rodríguez, is a repository of pre-recorded events while offensive techniques were executed on laboratory machines.
As expected, this project integrates perfectly with HELK and provides us with very interesting data to start hunting our threats. So, let’s go.
[Read more…]