🎉 Launch offer — 20% off every workbook & bundle. Applied automatically at checkout.
ciso.diy
R04 — The Defend Side preview
Cyber Range cyber rangeWazuhElasticSigma

R04 — The Defend Side

Instrument the range so a detection test actually means something. Log fidelity first, then Wazuh or Elastic with Velociraptor, Suricata and Zeek, driven by Atomic Red Team and Caldera, with detections written as portable Sigma and validated in CI against the corpus.

Volumes 01 through 03 all ended at the same handoff: and then you detect it. This is where that happens.

A detection you have not tested against the actual attack is a hypothesis, not a control. Most organisations run detections that have never once fired on the thing they claim to catch, because there was never a safe place to run the thing. The range's detection stack has one job production's does not: it is allowed to be attacked on purpose, repeatedly, with known ground truth. You authored the attack, so when the detection fires you know exactly what it fired on — and when it stays silent you know exactly what it missed.

Log fidelity comes before any tool, because everything rests on it. A detection test has three parts — the attack, the telemetry, and the rule — and people obsess over the rule, which is the last thing that matters. Most "our detection didn't work" turns out to be "our logging didn't capture it." Command-line logging and PowerShell script-block logging are off by default on Windows, and a range without them will happily pass a test that fails in production. Four telemetry domains, the configuration that makes or breaks each, and the one-time fidelity test that is the highest-leverage hour in the volume.

The stack: Wazuh or Elastic chosen by what you already run, because a detection validated on one backend is not automatically portable to the other — with the honest caveat that Wazuh's indexer is resource-hungry and will starve your AD lab if you do not cap its heap deliberately. Velociraptor for live forensics and hunt authoring. Suricata for the known-bad and Zeek for the behavioural, placed where they see range traffic without becoming an accidental egress path.

Adversary emulation at two scopes: Atomic Red Team as the unit test for detections, mapped directly to ATT&CK techniques, and Caldera as the integration test, chaining techniques into full operations. A detection that fires on the isolated atomic but drowns in an operation is a detection that will fail you in a real incident.

Detection-as-code and CI validation — the capability that compounds. Sigma as the portable format so a rule proven against a reproduced CVE deploys to production and to every client without a rewrite, wired to a pipeline that redeploys the corpus environment on every change and confirms the detection still fires. When a detection breaks because an environment updated or a log source shifted, you find out in CI rather than in an incident.

The agentic triage layer — missing entirely from most open-source SOC stacks, and exactly where the economics of a small practice break. The range is where you build and validate it safely, because you authored the attacks and therefore have labelled ground truth. Includes deliberately embedding hostile content in an attack to see what the triage layer does with it.

Closes with the repeatable purple-team loop, the three metrics that matter (coverage, time-to-detect, specificity), five worksheets and a readiness checklist.

What's included

  • PDF — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
One-time purchase
$149.00 $119.20 20% off
  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-08-31
Pages 5