weslambert / BlueCloud

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Home Page:https://blue.iknowjason.io

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Overview

Cyber Range deployment of HELK and Velociraptor! Automated terraform deployment of one system running HELK + Velociraptor server with one registered Windows endpoint in Azure or AWS. A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small HELK + Velociraptor R&D lab.

Use Cases

  • EDR Testing lab
  • Penetration Testing lab
  • SIEM / Threat Hunting / DFIR / Live Response lab with HELK + Velociraptor [1, 2]
  • Data Science research with HELK server, Jupyter notebooks
  • Detection Engineering research with Mordor [3, 4]

Documentation

Please see the full documentation for details and getting started with installation.

Full Documentation Site

About

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

https://blue.iknowjason.io

License:MIT License


Languages

Language:HTML 64.9%Language:HCL 12.0%Language:PowerShell 10.9%Language:JavaScript 7.2%Language:Python 4.7%Language:Smarty 0.2%Language:Shell 0.1%