SOC detection lab using Elastic SIEM + Fleet + Sysmon with detections, alerts, incident write-ups, and troubleshooting.
elasticsearch detection incident-response sysmon siem elastic fleet soc elastic-agent windows-telemetry detectionengineering elastic-alerts
-
Updated
Jan 3, 2026