Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting
NetwerkLABS

Powered By TEKGENX CONSULTING

  • ATTACK
    • PenTest
    • Web Pentest
    • C2 Frameworks
    • VulnLAB
  • DETECT
    • Detection Engineering
    • DFIR
    • EDR | SIEM | SOAR
    • Purple Teaming
    • MITRE ATT&CK
  • DEFEND
    • CTEM
    • Attack Surface Management (ASM)
    • Network Infrastructure
    • Vulnerability Management
    • WAF | Firewalls | IDS/IPS
  • LEARNING PATHS
    • Wazuh SIEM & XDR
    • Attack & Defend AD
    • Cheat Sheets
  • GRC
    • ISO/IEC 27001
    • NIS2 | CyFUN
    • NIST
    • CIS Controls
  • CTI
    • Threat Intel
    • CyBER-NEWS
Subscribe

Elastic SIEM

  • Home
  • BLUE TEAM
  • Intrusion Detection and Response
  • Elastic SIEM
Practical Threat Hunting using Elastic SIEM: Hunting for Stuxbot
Posted inElastic SIEM Threat Hunting Threat Detection and Incident Response

Practical Threat Hunting using Elastic SIEM: Hunting for Stuxbot

Based on the INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC module from HTB-Academy Hunting for Stuxbot The Stuxbot cybercrime group operates with a broad scope, seizing upon opportunities as they arise, without any specific targeting…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Elastic, Threat_hunting
Posted inDETECT Elastic SIEM

Elastic SIEM: Developing Dashboards & Visualization

Use case 1: Failed Logon Attempts (Disabled Users) https://youtu.be/7Uyqek-FdwI Use case 2: Failed Logon Attempts (using Admin Accounts) https://youtu.be/UGRmsoqk0EM Use case 3: Successful RDP Logon Related To Service Accounts https://youtu.be/eRjA6TpEryk Use case 4: Users Added Or…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SIEM, Elastic, Threat_hunting
Posted inElastic SIEM BLUE TEAM DETECT

SIEM Use cases

How To Build SIEM Use Cases Comprehend your needs, risks, and establish alerts for monitoring all necessary systems accordingly. Determine the priority and impact, then map the alert to the kill chain or MITRE framework. Establish…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SIEM, Elastic, Usecase

Recent Posts

  • Using MITRE ATT&CK Navigator to Strengthen Threat Modelling [PART: II]
  • 8 LOLBins Every Threat Hunter Should Know
  • Living Off the Land (LOTL) Resources
  • Volatility3: Memory Forensics Cheatsheet
  • Misbehaving binaries: Hunting LOLBins 

Categories

AD AD attacks Atomic RED brute-force c2 caldera CISO dfir Elastic hydra linux NIST red-team SIEM splunk Threat Intel threat_detection vulnhub wazuh wireshark

Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by