logo

At Home Detection Engineering Lab for Beginners

ID: e45d8597-3de1-59f8-83c1-91a77b2330a2

STIX ID: report--e45d8597-3de1-59f8-83c1-91a77b2330a2

Feed Name: Black Hills Infosec Blog

Date Published: 2024-05-02

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post provides a step-by-step guide to building a small SIEM lab with VirtualBox, a Wazuh OVA manager, and a Windows endpoint, then using Atomic Red Team’s Invoke-Atomic to simulate MITRE ATT&CK techniques (e.g., credential dumping) and validate detections by observing registry integrity alerts in Wazuh—illustrating how to identify detection gaps and tune rules for better visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.