Tyler Morris
Tyler Morris
Verify that logs are being processed and collected over the two week test period.
Based on recent requests from various LME users review/modify the LME Wazuh agent docs for clarity. https://github.com/cisagov/LME/blob/main/docs/markdown/agents/wazuh-agent-management.md - [ ] Review for grammar and spelling issues - [ ] Review...
Based on recent requests from various LME users review/modify the LME Elastic agent docs for clarity. https://github.com/cisagov/LME/blob/main/docs/markdown/agents/elastic-agent-management.md - [ ] Review for grammar and spelling issues - [ ] Review...
Provide environment/scripts for minimega to deploy repeatable experiments.
What type of attacks do LME users want to see demonstrated? We need to formulate a list of 3 initial threats to emulate.
Run 20 virtual machines over a 2 week period.
Defender is turned off by default when installing elastic agent. This may not be the desired outcome and a fix is being worked to stop this from occuring by default.
Verify that information is being displayed in dashboards.
Run small scale attack against specific VMs within the enviorment to test logging within dashboards.
Setup Mitre Caldera and peform simple use case testing within the development environment.