├── ELK-cheatsheet.md ├── ELK-resources.md ├── README.md ├── filebeat └── filebeat.yml ├── logstash └── apache-geoip.conf ├── temp └── recon.ps1 └── winlogbeat └── winlogbeat.yml /ELK-cheatsheet.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/ELK-cheatsheet.md -------------------------------------------------------------------------------- /ELK-resources.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/ELK-resources.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/README.md -------------------------------------------------------------------------------- /filebeat/filebeat.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/filebeat/filebeat.yml -------------------------------------------------------------------------------- /logstash/apache-geoip.conf: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/logstash/apache-geoip.conf -------------------------------------------------------------------------------- /temp/recon.ps1: -------------------------------------------------------------------------------- 1 | $ip = Invoke-RestMethod http://ipinfo.io/json | Select -exp ip 2 | -------------------------------------------------------------------------------- /winlogbeat/winlogbeat.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/PolitoInc/ELK-Hunting/HEAD/winlogbeat/winlogbeat.yml --------------------------------------------------------------------------------