March 2022
Intermediate to advanced
752 pages
18h 47m
English
In this chapter, we cover the following topics:
• Threat hunting and labs
• Basic threat hunting lab: DetectionLab
• Extending your lab with HELK
What is a threat hunting lab? Threat hunting will be covered in the next chapter, but essentially it is the systematic hunting of threats that are not otherwise apparent in the network through the use of technologies such as SIEM, IDS, IPS, and so on. In order to learn this vital skill set, you will need a safe environment in which to play—a lab environment with all the required tools installed, in an automated deployment, that may be set up and torn down quickly. To this end, we will explore the latest and best options for your threat hunting lab. ...