Test Environment Builder

Build adversary emulation lab environments across Splunk, Elastic Security, and Microsoft Sentinel.

471|74|Updated Jan 13, 2026
One-click install
npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill test-environment-builder
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Test Environment Builder
Source: https://github.com/MHaggis/Security-Detections-MCP/tree/main/.claude/skills/attack-range-builder
Command: npx skills add https://github.com/MHaggis/Security-Detections-MCP --skill test-environment-builder

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps you build and manage adversary emulation lab environments tailored to your specific SIEM, ensuring your security detections are tested against realistic telemetry.

Core Features & Use Cases

  • SIEM-Agnostic Lab Building: Supports Splunk, Elastic Security, Microsoft Sentinel, and generic Docker setups.
  • Data Source Mapping: Guides you in identifying and configuring the infrastructure needed to generate specific log sources required by your detections.
  • Workflow Automation: Provides step-by-step guidance for configuring and deploying lab environments using tools like Terraform, Ansible, and Docker Compose.
  • Use Case: You need to test a new Splunk detection rule that relies on Sysmon process creation events. This skill will guide you through configuring Attack Range to include a Windows server with Sysmon installed and the necessary Splunk forwarder.

Quick Start

Use the Test Environment Builder skill to set up a Splunk Attack Range environment with one Windows server and Sysmon enabled.

Frequently Asked Questions about Test Environment Builder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an adversary emulation lab for Splunk?

Build an adversary emulation lab for Splunk using this skill to configure Attack Range with Terraform and Docker Compose. It provides step-by-step workflows to deploy Windows servers, install Sysmon, and configure Splunk forwarders for security detection testing.

Can I configure Elastic Security and Microsoft Sentinel lab environments?

Yes, you can configure Elastic Security and Microsoft Sentinel lab environments. This SIEM-agnostic skill supports multiple platforms, mapping required data sources to infrastructure components and guiding deployment for comprehensive security testing.

How do I map data sources to infrastructure for detection engineering?

Map data sources to infrastructure for detection engineering using this skill to identify required log sources and configure the corresponding components. It provides guidance for setting up Windows, Linux, network sensors, and cloud resources to generate specific telemetry.

What is the best way to automate deployment of a SIEM testing environment?

Automate deployment of a SIEM testing environment using this skill for step-by-step guidance with Terraform, Ansible, and Docker Compose. It facilitates configuring and deploying lab infrastructure across multiple SIEM platforms to ensure realistic telemetry generation.

Does this skill work with generic Docker setups for security testing?

Yes, this skill works with generic Docker setups for security testing. It supports configuring lab environments using Docker Compose alongside specific SIEM platforms like Splunk, Elastic Security, and Microsoft Sentinel for adversary emulation.

How do I test a Splunk detection rule that relies on Sysmon process creation events?

Test a Splunk detection rule relying on Sysmon process creation events by using this skill to configure Attack Range with a Windows server. It guides you through installing Sysmon and deploying the necessary Splunk forwarder to generate the required telemetry.