Adversary Lab

Security theory is useless if you can’t prove detection works under pressure.

MITRE ATT&CK Sigma Wazuh Elastic

Highlights

Problem: Security theory means little without hands-on validation of detection and response workflows.

Solution: Simulated 10+ MITRE ATT&CK techniques across Windows and Linux, collecting telemetry in Wazuh and Elastic.

Impact: Authored 10+ custom Sigma rules mapped to technique IDs.

Story

Role: Solo Security Researcher

Timeframe: 2026

Stack

MITRE ATT&CK, Sigma, Wazuh, Elastic

Next project →