Reader small image

You're reading from  Practical Threat Intelligence and Data-Driven Threat Hunting

Product typeBook
Published inFeb 2021
PublisherPackt
ISBN-139781838556372
Edition1st Edition
Right arrow
Author (1)
Valentina Costa-Gazcón
Valentina Costa-Gazcón
author image
Valentina Costa-Gazcón

Valentina Costa-Gazcón is a cyber threat intelligence analyst who specializes in tracking Advanced Persistent Threats (APTs) worldwide, using the MITRE ATT&CK Framework to analyze their tools, tactics, techniques, and procedures (TTPs). She is a self-taught developer and threat hunter with a degree in translation and interpretation from the Universidad de Málaga (UMA) and a cyber security diploma from Argentina's Universidad Tecnológica Nacional (UTN). Valentina also is one of the founders of the BlueSpace community (BlueSpaceSec) and one of the core members of Open Threat Research, founded by Roberto Rodriguez (OTR_Community).
Read more about Valentina Costa-Gazcón

Right arrow

The HELK – an open source tool by Roberto Rodriguez

The Hunting ELK (HELK) is an open source hunting platform designed and developed by Roberto Rodriguez. Some of the advantages of using the HELK over a plain ELK environment are that the HELK has been built with advanced analytics capabilities and can be used both in research environments and in large production environments. The project, although widely adopted and praised, it still in its alpha stage of development and is expected to be subject to many changes:

Figure 7.72 – The HELK infrastructure by Roberto Rodriguez

Getting started with the HELK

If you opt to directly install the HELK, you will still need to deploy an Ubuntu machine. You will need to download the Linux distro. I'm going to use Ubuntu 18.04 (https://releases.ubuntu.com/), but you can use any of the other operating systems that the HELK has been optimized for; that is, Ubuntu 18.04, Ubuntu 16, CentOS 7, and CentOS 8...

lock icon
The rest of the page is locked
Previous PageNext Chapter
You have been reading a chapter from
Practical Threat Intelligence and Data-Driven Threat Hunting
Published in: Feb 2021Publisher: PacktISBN-13: 9781838556372

Author (1)

author image
Valentina Costa-Gazcón

Valentina Costa-Gazcón is a cyber threat intelligence analyst who specializes in tracking Advanced Persistent Threats (APTs) worldwide, using the MITRE ATT&CK Framework to analyze their tools, tactics, techniques, and procedures (TTPs). She is a self-taught developer and threat hunter with a degree in translation and interpretation from the Universidad de Málaga (UMA) and a cyber security diploma from Argentina's Universidad Tecnológica Nacional (UTN). Valentina also is one of the founders of the BlueSpace community (BlueSpaceSec) and one of the core members of Open Threat Research, founded by Roberto Rodriguez (OTR_Community).
Read more about Valentina Costa-Gazcón