Elastic Stack Lab
This lab simulates a real-world security incident where attackers compromised a network through SSH brute-force attacks. Students will use Kibana dashboards and Elastic Stack to analyze authentication logs, track attacker movements, identify exploitation techniques, and trace post-compromise activities including privilege escalation and lateral movement.
By CyberTask ยท Easy level
17
Tasks
1
Sections
161
Points
1 hr
Duration
What You'll Learn
- Analyze authentication logs using Kibana dashboards
- Identify brute-force attack patterns and indicators
- Map attack techniques to MITRE ATT&CK
- Trace post-exploitation commands and file operations
- Investigate lateral movement and privilege escalation
- Correlate log events across multiple systems
Prerequisites
- Basic Linux command line knowledge
- Understanding of SSH authentication concepts
- Familiarity with log analysis fundamentals
- Basic cybersecurity incident response concepts
Tools & Technologies
Kibana
Elastic Stack
auditd
vim
Ready to Begin?
Sign in or create an account to start this lab and earn points.