Overview of Detection Lab features
masterDetection Lab is a pre-configured Windows domain designed for defenders to practice security monitoring and introspection. It includes several integrated security tools and logging configurations:
- Microsoft Advanced Threat Analytics (ATA): Installed on the WEF machine with a lightweight ATA gateway on the DC.
- Splunk: Pre-installed with forwarders, pre-created indexes, and configured Technology Add-ons.
- Windows Auditing: Custom GPO configuration for command line process auditing and OS-level logging.
- Windows Event Forwarding (WEF): Implements Palantir's WEF subscriptions and custom channels.
- PowerShell Logging: Transcript logging is enabled; logs are stored at
\wef\pslogs. - osquery & Fleet: osquery is installed on all hosts and configured to connect to a Fleet server via TLS (using Palantir's osquery configuration).
- Sysmon: Installed and configured using Olaf Hartong's sysmon-modular configuration.
- Autoruns Logging: All autostart items are logged to Windows Event Logs via
AutorunsToWinEventLog. - Network Monitoring: Zeek and Suricata are pre-configured for network traffic monitoring and alerting.
- Remote Access: Apache Guacamole is installed for browser-based access to all hosts.