OPFORGE
Scenarios Architecture Lab Environment Adversary Emulation Detection Engineering Documentation

Logstash

OPFORGE-v2 Detection Validation: Windows Telemetry, Sysmon, and PowerShell Execution

OPFORGE-v2 moved from logging-stack IOC to repeatable endpoint detection validation using Windows Event Logs, Sysmon, Winlogbeat, Logstash, OpenSearch, and OpenSearch Dashboards.

Controlled Filebeat test event -> Logstash Beats input -> OpenSearch -> OpenSearch Dashboards

OPFORGE Adversary Emulation • Detection Validation • Cyber Experimentation