Elastic Stack Lab

Elastic Stack Lab

This lab simulates a real-world security incident where attackers compromised a network through SSH brute-force attacks. Students will use Kibana dashboards and Elastic Stack to analyze authentication logs, track attacker movements, identify exploitation techniques, and trace post-compromise activities including privilege escalation and lateral movement.

By CyberTask ยท Easy level

17 Tasks
1 Sections
161 Points
1 hr Duration

What You'll Learn

  • Analyze authentication logs using Kibana dashboards
  • Identify brute-force attack patterns and indicators
  • Map attack techniques to MITRE ATT&CK
  • Trace post-exploitation commands and file operations
  • Investigate lateral movement and privilege escalation
  • Correlate log events across multiple systems

Prerequisites

  • Basic Linux command line knowledge
  • Understanding of SSH authentication concepts
  • Familiarity with log analysis fundamentals
  • Basic cybersecurity incident response concepts
Tools & Technologies
Kibana
Elastic Stack
auditd
vim

Ready to Begin?

Sign in or create an account to start this lab and earn points.

Login to Start
Loading...