How To Deploy Windows Optics: Commands, Downloads, Instructions, and Screenshots
ID: 6bd6e849-91d8-5e8e-9e40-57fee1e757a9
STIX ID: report--6bd6e849-91d8-5e8e-9e40-57fee1e757a9
Feed Name: Black Hills Infosec Blog
This guide provides a step-by-step walkthrough to build a Windows-focused detection lab, including deploying a pfSense gateway, a Windows Server 2016 domain controller, a Windows 10 workstation, and an Ubuntu-based Elastic/HELK stack. It details configuring Sysmon with Olaf Hartong’s modular rules, applying enhanced Windows audit policies via GPOs, setting up Windows Event Forwarding and a Windows Event Collector with Palantir’s event channels, enabling WinRM and firewall rules, and installing Winlogbeat to ship logs into Elastic/Kibana—resulting in a low-cost, comprehensive endpoint telemetry pipeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
