logo

How To Deploy Windows Optics: Commands, Downloads, Instructions, and Screenshots

ID: 6bd6e849-91d8-5e8e-9e40-57fee1e757a9

STIX ID: report--6bd6e849-91d8-5e8e-9e40-57fee1e757a9

Feed Name: Black Hills Infosec Blog

Date Published: 2020-06-17

Date Updated: 2026-04-27

Author: BHIS

...
...

This guide provides a step-by-step walkthrough to build a Windows-focused detection lab, including deploying a pfSense gateway, a Windows Server 2016 domain controller, a Windows 10 workstation, and an Ubuntu-based Elastic/HELK stack. It details configuring Sysmon with Olaf Hartong’s modular rules, applying enhanced Windows audit policies via GPOs, setting up Windows Event Forwarding and a Windows Event Collector with Palantir’s event channels, enabling WinRM and firewall rules, and installing Winlogbeat to ship logs into Elastic/Kibana—resulting in a low-cost, comprehensive endpoint telemetry pipeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.